Show filters
323 Total Results
Displaying 231-240 of 323
Sort by:
Attacker Value
Unknown

CVE-2016-8685

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
The findnext function in decompose.c in potrace 1.13 allows remote attackers to cause a denial of service (invalid memory access and crash) via a crafted BMP image.
0
Attacker Value
Unknown

CVE-2016-8699

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8700, CVE-2016-8701, CVE-2016-8702, and CVE-2016-8703.
0
Attacker Value
Unknown

CVE-2016-8694

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8695 and CVE-2016-8696.
0
Attacker Value
Unknown

CVE-2016-8695

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
The bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted BMP image, a different vulnerability than CVE-2016-8694 and CVE-2016-8696.
0
Attacker Value
Unknown

CVE-2016-8701

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8698, CVE-2016-8699, CVE-2016-8700, CVE-2016-8702, and CVE-2016-8703.
0
Attacker Value
Unknown

CVE-2016-8698

Disclosure Date: January 31, 2017 (last updated November 25, 2024)
Heap-based buffer overflow in the bm_readbody_bmp function in bitmap_io.c in potrace before 1.13 allows remote attackers to have unspecified impact via a crafted BMP image, a different vulnerability than CVE-2016-8699, CVE-2016-8700, CVE-2016-8701, CVE-2016-8702, and CVE-2016-8703.
0
Attacker Value
Unknown

CVE-2016-1000136

Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin heat-trackr v1.0
0
Attacker Value
Unknown

CVE-2014-6276

Disclosure Date: April 13, 2016 (last updated November 25, 2024)
schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.
0
Attacker Value
Unknown

CVE-2015-6751

Disclosure Date: August 31, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Time Tracker module 7.x-1.x before 7.x-1.4 for Drupal allow remote authenticated users with certain permissions to inject arbitrary web script or HTML via a (1) note added to a time entry or an (2) activity used to categorize time tracker entries.
0
Attacker Value
Unknown

CVE-2015-4362

Disclosure Date: June 15, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in tracking_code.admin.inc in the Tracking Code module 7.x-1.x before 7.x-1.6 for Drupal allows remote attackers to hijack the authentication of administrators for requests that disable tracking codes via unspecified vectors.
0