Show filters
699 Total Results
Displaying 221-230 of 699
Sort by:
Attacker Value
Unknown

CVE-2022-0865

Disclosure Date: March 10, 2022 (last updated February 23, 2025)
Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.
Attacker Value
Unknown

CVE-2021-25039

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The WordPress Multisite Content Copier/Updater WordPress plugin before 2.1.0 does not sanitise and escape the wmcc_content_type, wmcc_source_blog and wmcc_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2021-25038

Disclosure Date: March 07, 2022 (last updated February 23, 2025)
The WordPress Multisite User Sync/Unsync WordPress plugin before 2.1.2 does not sanitise and escape the wmus_source_blog and wmus_record_per_page parameters before outputting them back in attributes, leading to Reflected Cross-Site Scripting issues
Attacker Value
Unknown

CVE-2021-3623

Disclosure Date: March 02, 2022 (last updated February 23, 2025)
A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The highest threat from this vulnerability is to system availability.
Attacker Value
Unknown

CVE-2022-0562

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit 561599c.
Attacker Value
Unknown

CVE-2022-0561

Disclosure Date: February 11, 2022 (last updated February 23, 2025)
Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with commit eecb0712.
Attacker Value
Unknown

CVE-2022-22844

Disclosure Date: January 10, 2022 (last updated February 23, 2025)
LibTIFF 4.3.0 has an out-of-bounds read in _TIFFmemcpy in tif_unix.c in certain situations involving a custom tag and 0x0200 as the second word of the DE field.
Attacker Value
Unknown

CVE-2021-45927

Disclosure Date: January 01, 2022 (last updated February 23, 2025)
MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd6e029ee0) in mdb_numeric_to_string (called from mdb_xfer_bound_data and _mdb_attempt_bind).
Attacker Value
Unknown

CVE-2021-45926

Disclosure Date: January 01, 2022 (last updated February 23, 2025)
MDB Tools (aka mdbtools) 0.9.2 has a stack-based buffer overflow (at 0x7ffd0c689be0) in mdb_numeric_to_string (called from mdb_xfer_bound_data and _mdb_attempt_bind).
Attacker Value
Unknown

CVE-2021-24945

Disclosure Date: December 13, 2021 (last updated February 23, 2025)
The Like Button Rating ♥ LikeBtn WordPress plugin before 2.6.38 does not have any authorisation and CSRF checks in the likebtn_export_votes AJAX action, which could allow any authenticated user, such as subscriber, to get a list of email and IP addresses of people who liked content from the blog.