Show filters
1,232 Total Results
Displaying 241-250 of 1,232
Sort by:
Attacker Value
Unknown

CVE-2022-24720

Disclosure Date: March 01, 2022 (last updated February 23, 2025)
image_processing is an image processing wrapper for libvips and ImageMagick/GraphicsMagick. Prior to version 1.12.2, using the `#apply` method from image_processing to apply a series of operations that are coming from unsanitized user input allows the attacker to execute shell commands. This method is called internally by Active Storage variants, so Active Storage is vulnerable as well. The vulnerability has been fixed in version 1.12.2 of image_processing. As a workaround, users who process based on user input should always sanitize the user input by allowing only a constrained set of operations.
Attacker Value
Unknown

CVE-2021-3610

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
Attacker Value
Unknown

CVE-2021-3596

Disclosure Date: February 24, 2022 (last updated February 23, 2025)
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
Attacker Value
Unknown

CVE-2022-24086

Disclosure Date: February 13, 2022 (last updated February 23, 2025)
Adobe Commerce versions 2.4.3-p1 (and earlier) and 2.3.7-p2 (and earlier) are affected by an improper input validation vulnerability during the checkout process. Exploitation of this issue does not require user interaction and could result in arbitrary code execution.
0
Attacker Value
Unknown

CVE-2021-46389

Disclosure Date: February 07, 2022 (last updated February 23, 2025)
IIPImage High Resolution Streaming Image Server prior to commit 882925b295a80ec992063deffc2a3b0d803c3195 is affected by an integer overflow in iipsrv.fcgi through malformed HTTP query parameters.
Attacker Value
Unknown

CVE-2021-24888

Disclosure Date: November 23, 2021 (last updated February 23, 2025)
The ImageBoss WordPress plugin before 3.0.6 does not sanitise and escape its Source Name setting, which could allow high privilege users to perform Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2021-24644

Disclosure Date: November 23, 2021 (last updated February 23, 2025)
The Images to WebP WordPress plugin before 1.9 does not validate or sanitise the tab parameter before passing it to the include() function, which could lead to a Local File Inclusion issue
Attacker Value
Unknown

CVE-2021-24641

Disclosure Date: November 23, 2021 (last updated February 23, 2025)
The Images to WebP WordPress plugin before 1.9 does not have CSRF checks in place when performing some administrative actions, which could result in modification of plugin settings, Denial-of-Service, as well as arbitrary image conversion
Attacker Value
Unknown

CVE-2021-3962

Disclosure Date: November 19, 2021 (last updated February 23, 2025)
A flaw was found in ImageMagick where it did not properly sanitize certain input before using it to invoke convert processes. This flaw allows an attacker to create a specially crafted image that leads to a use-after-free vulnerability when processed by ImageMagick. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Attacker Value
Unknown

CVE-2020-21573

Disclosure Date: November 02, 2021 (last updated February 23, 2025)
An issue was discoverered in in abhijitnathwani image-processing v0.1.0, allows local attackers to cause a denial of service via a crafted image file.