Show filters
733 Total Results
Displaying 411-420 of 733
Sort by:
Attacker Value
Unknown
CVE-2017-18219
Disclosure Date: March 05, 2018 (last updated November 08, 2023)
An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted file that triggers an attempt at a large png_pixels array allocation.
0
Attacker Value
Unknown
CVE-2017-18220
Disclosure Date: March 05, 2018 (last updated November 08, 2023)
The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/blob.c CloseBlob use-after-free) or possibly have unspecified other impact via a crafted file, a related issue to CVE-2017-11403.
0
Attacker Value
Unknown
CVE-2018-7448
Disclosure Date: February 26, 2018 (last updated November 26, 2024)
Remote code execution vulnerability in /cmsms-2.1.6-install.php/index.php in CMS Made Simple version 2.1.6 allows remote attackers to inject arbitrary PHP code via the "timezone" parameter in step 4 of a fresh installation procedure.
0
Attacker Value
Unknown
CVE-2017-16670
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
0
Attacker Value
Unknown
CVE-2018-6799
Disclosure Date: February 07, 2018 (last updated November 08, 2023)
The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used.
0
Attacker Value
Unknown
CVE-2018-5963
Disclosure Date: January 25, 2018 (last updated November 26, 2024)
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/addbookmark.php via the title parameter.
0
Attacker Value
Unknown
CVE-2018-5964
Disclosure Date: January 25, 2018 (last updated November 26, 2024)
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter.
0
Attacker Value
Unknown
CVE-2018-5965
Disclosure Date: January 25, 2018 (last updated November 26, 2024)
CMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_errors parameter.
0
Attacker Value
Unknown
CVE-2018-5955
Disclosure Date: January 21, 2018 (last updated November 26, 2024)
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest/user/ URI.
0
Attacker Value
Unknown
CVE-2018-5685
Disclosure Date: January 14, 2018 (last updated November 26, 2024)
In GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers could leverage this vulnerability to cause a denial of service via an image file with a crafted bit-field mask value.
0