Show filters
733 Total Results
Displaying 491-500 of 733
Sort by:
Attacker Value
Unknown
CVE-2017-9863
Disclosure Date: August 05, 2017 (last updated November 08, 2023)
An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in the inverters (for example, issuing a POST request to change the user password). All Sunny Explorer settings available to the authenticated user are also available to the attacker. (In some cases, this also includes changing settings that the user has no access to.) This may result in complete compromise of the device. NOTE: the vendor reports that exploitation is unlikely because Sunny Explorer is used only rarely. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected
0
Attacker Value
Unknown
CVE-2017-11722
Disclosure Date: July 28, 2017 (last updated November 08, 2023)
The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was inconsistent with its indentation. This resulted in a logging statement executing outside of a loop, and consequently using an invalid array index corresponding to the loop's exit condition.
0
Attacker Value
Unknown
CVE-2017-11636
Disclosure Date: July 26, 2017 (last updated November 26, 2024)
GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical widths.
0
Attacker Value
Unknown
CVE-2017-11642
Disclosure Date: July 26, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11638.
0
Attacker Value
Unknown
CVE-2017-11643
Disclosure Date: July 26, 2017 (last updated November 26, 2024)
GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in coders/cmyk.c when processing multiple frames that have non-identical widths.
0
Attacker Value
Unknown
CVE-2017-11641
Disclosure Date: July 26, 2017 (last updated November 26, 2024)
GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent Cache (MPC) files.
0
Attacker Value
Unknown
CVE-2017-11638
Disclosure Date: July 26, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 has a segmentation violation in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11642.
0
Attacker Value
Unknown
CVE-2017-11637
Disclosure Date: July 26, 2017 (last updated November 26, 2024)
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WritePCLImage() function in coders/pcl.c during writes of monochrome images.
0
Attacker Value
Unknown
CVE-2017-11404
Disclosure Date: July 18, 2017 (last updated November 26, 2024)
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php.
0
Attacker Value
Unknown
CVE-2017-11405
Disclosure Date: July 18, 2017 (last updated November 26, 2024)
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/moduleinterface.php in which type=image is changed to type=file.
0