Show filters
1,232 Total Results
Displaying 231-240 of 1,232
Sort by:
Attacker Value
Unknown

CVE-2022-32547

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior.
Attacker Value
Unknown

CVE-2022-32546

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Attacker Value
Unknown

CVE-2022-32545

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
Attacker Value
Unknown

CVE-2022-1765

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Hot Linked Image Cacher WordPress plugin through 1.16 is vulnerable to CSRF. This can be used to store / cache images from external domains on the server, which could lead to legal risks (due to copyright violations or licensing rules).
Attacker Value
Unknown

CVE-2022-1221

Disclosure Date: May 23, 2022 (last updated February 23, 2025)
The Gwyn's Imagemap Selector WordPress plugin through 0.3.3 does not sanitise and escape some parameters before outputting them back in attributes, leading to a Reflected Cross-Site Scripting.
Attacker Value
Unknown

CVE-2022-1216

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
The Advanced Image Sitemap WordPress plugin through 1.2 does not sanitise and escape the PHP_SELF PHP variable before outputting it back in an attribute in an admin page, leading to Reflected Cross-Site Scripting.
Attacker Value
Unknown

CVE-2022-28463

Disclosure Date: May 08, 2022 (last updated February 23, 2025)
ImageMagick 7.1.0-27 is vulnerable to Buffer Overflow.
Attacker Value
Unknown

CVE-2022-1114

Disclosure Date: April 29, 2022 (last updated February 23, 2025)
A heap-use-after-free flaw was found in ImageMagick's RelinquishDCMInfo() function of dcm.c file. This vulnerability is triggered when an attacker passes a specially crafted DICOM image file to ImageMagick for conversion, potentially leading to information disclosure and a denial of service.
Attacker Value
Unknown

CVE-2021-4219

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A flaw was found in ImageMagick. The vulnerability occurs due to improper use of open functions and leads to a denial of service. This flaw allows an attacker to crash the system.
Attacker Value
Unknown

CVE-2022-0478

Disclosure Date: March 14, 2022 (last updated February 23, 2025)
The Event Manager and Tickets Selling for WooCommerce WordPress plugin before 3.5.8 does not validate and escape the post_author_gutenberg parameter before using it in a SQL statement when creating/editing events, which could allow users with a role as low as contributor to perform SQL Injection attacks