Show filters
733 Total Results
Displaying 491-500 of 733
Sort by:
Attacker Value
Unknown

CVE-2017-9863

Disclosure Date: August 05, 2017 (last updated November 08, 2023)
An issue was discovered in SMA Solar Technology products. If a user simultaneously has Sunny Explorer running and visits a malicious host, cross-site request forgery can be used to change settings in the inverters (for example, issuing a POST request to change the user password). All Sunny Explorer settings available to the authenticated user are also available to the attacker. (In some cases, this also includes changing settings that the user has no access to.) This may result in complete compromise of the device. NOTE: the vendor reports that exploitation is unlikely because Sunny Explorer is used only rarely. Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected
0
Attacker Value
Unknown

CVE-2017-11722

Disclosure Date: July 28, 2017 (last updated November 08, 2023)
The WriteOnePNGImage function in coders/png.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file, because the program's actual control flow was inconsistent with its indentation. This resulted in a logging statement executing outside of a loop, and consequently using an invalid array index corresponding to the loop's exit condition.
0
Attacker Value
Unknown

CVE-2017-11636

Disclosure Date: July 26, 2017 (last updated November 26, 2024)
GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical widths.
0
Attacker Value
Unknown

CVE-2017-11642

Disclosure Date: July 26, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11638.
0
Attacker Value
Unknown

CVE-2017-11643

Disclosure Date: July 26, 2017 (last updated November 26, 2024)
GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in coders/cmyk.c when processing multiple frames that have non-identical widths.
0
Attacker Value
Unknown

CVE-2017-11641

Disclosure Date: July 26, 2017 (last updated November 26, 2024)
GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixel_cache.c during writing of Magick Persistent Cache (MPC) files.
0
Attacker Value
Unknown

CVE-2017-11638

Disclosure Date: July 26, 2017 (last updated November 08, 2023)
GraphicsMagick 1.3.26 has a segmentation violation in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11642.
0
Attacker Value
Unknown

CVE-2017-11637

Disclosure Date: July 26, 2017 (last updated November 26, 2024)
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WritePCLImage() function in coders/pcl.c during writes of monochrome images.
0
Attacker Value
Unknown

CVE-2017-11404

Disclosure Date: July 18, 2017 (last updated November 26, 2024)
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a FileManager action to admin/moduleinterface.php.
0
Attacker Value
Unknown

CVE-2017-11405

Disclosure Date: July 18, 2017 (last updated November 26, 2024)
In CMS Made Simple (CMSMS) 2.2.2, remote authenticated administrators can upload a .php file via a CMSContentManager action to admin/moduleinterface.php, followed by a FilePicker action to admin/moduleinterface.php in which type=image is changed to type=file.
0