Show filters
733 Total Results
Displaying 341-350 of 733
Sort by:
Attacker Value
Unknown

CVE-2019-3833

Disclosure Date: March 14, 2019 (last updated November 27, 2024)
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
Attacker Value
Unknown

CVE-2019-3816

Disclosure Date: March 14, 2019 (last updated November 27, 2024)
Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this vulnerability by sending a specially crafted HTTP request to openwsman server.
Attacker Value
Unknown

CVE-2019-9693 - CMS Made Simple (CMSMS) SQL Injection

Disclosure Date: March 11, 2019 (last updated November 27, 2024)
In CMS Made Simple (CMSMS) before 2.2.10, an authenticated user can achieve SQL Injection in class.showtime2_data.php via the functions _updateshow (parameter show_id), _inputshow (parameter show_id), _Getshowinfo (parameter show_id), _Getpictureinfo (parameter picture_id), _AdjustNameSeq (parameter shownumber), _Updatepicture (parameter picture_id), and _Deletepicture (parameter picture_id).
0
Attacker Value
Unknown

CVE-2019-9062

Disclosure Date: February 23, 2019 (last updated November 10, 2023)
PHP Scripts Mall Online Food Ordering Script 1.0 has Cross-Site Request Forgery (CSRF) in my-account.php.
0
Attacker Value
Unknown

CVE-2019-7397

Disclosure Date: February 05, 2019 (last updated November 27, 2024)
In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.
Attacker Value
Unknown

CVE-2015-9276

Disclosure Date: January 16, 2019 (last updated November 27, 2024)
SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker's email, which contained a malicious payload. Therefore, users' passwords could be reset by using an XSS attack, as the password reset page did not need the current password.
0
Attacker Value
Unknown

CVE-2018-20464

Disclosure Date: December 25, 2018 (last updated November 27, 2024)
There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.
0
Attacker Value
Unknown

CVE-2018-19597

Disclosure Date: December 19, 2018 (last updated November 27, 2024)
CMS Made Simple 2.2.8 allows XSS via an uploaded SVG document, a related issue to CVE-2017-16798.
0
Attacker Value
Unknown

CVE-2018-20189

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization.
0
Attacker Value
Unknown

CVE-2018-20184

Disclosure Date: December 17, 2018 (last updated November 27, 2024)
In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification.
0