Show filters
733 Total Results
Displaying 511-520 of 733
Sort by:
Attacker Value
Unknown

CVE-2017-10794

Disclosure Date: July 02, 2017 (last updated November 26, 2024)
When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occurs, related to QuantumTransferMode.
0
Attacker Value
Unknown

CVE-2017-9668

Disclosure Date: June 18, 2017 (last updated November 26, 2024)
In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via the description parameter in an addgroup action.
0
Attacker Value
Unknown

CVE-2017-9098

Disclosure Date: May 19, 2017 (last updated November 26, 2024)
ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initialization step in the ReadRLEImage function in coders/rle.c.
Attacker Value
Unknown

CVE-2017-8912

Disclosure Date: May 12, 2017 (last updated November 08, 2023)
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a bug.
0
Attacker Value
Unknown

CVE-2017-7909

Disclosure Date: May 06, 2017 (last updated November 26, 2024)
A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept requests and bypass authentication to access restricted web pages.
0
Attacker Value
Unknown

CVE-2017-2096

Disclosure Date: April 28, 2017 (last updated November 26, 2024)
smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Attacker Value
Unknown

CVE-2017-7628

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability).
0
Attacker Value
Unknown

CVE-2017-7627

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
The "Smart related articles" extension 1.1 for Joomla! does not prevent direct requests to dialog.php (there is a missing _JEXEC check).
0
Attacker Value
Unknown

CVE-2017-7626

Disclosure Date: April 13, 2017 (last updated November 26, 2024)
The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET Method).
0
Attacker Value
Unknown

CVE-2016-5682

Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.