Show filters
733 Total Results
Displaying 511-520 of 733
Sort by:
Attacker Value
Unknown
CVE-2017-10794
Disclosure Date: July 02, 2017 (last updated November 26, 2024)
When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occurs, related to QuantumTransferMode.
0
Attacker Value
Unknown
CVE-2017-9668
Disclosure Date: June 18, 2017 (last updated November 26, 2024)
In admin\addgroup.php in CMS Made Simple 2.1.6, when adding a user group, there is no XSS filtering, resulting in storage-type XSS generation, via the description parameter in an addgroup action.
0
Attacker Value
Unknown
CVE-2017-9098
Disclosure Date: May 19, 2017 (last updated November 26, 2024)
ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initialization step in the ReadRLEImage function in coders/rle.c.
0
Attacker Value
Unknown
CVE-2017-8912
Disclosure Date: May 12, 2017 (last updated November 08, 2023)
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTag functions. NOTE: the vendor reportedly has stated this is "a feature, not a bug.
0
Attacker Value
Unknown
CVE-2017-7909
Disclosure Date: May 06, 2017 (last updated November 26, 2024)
A Use of Client-Side Authentication issue was discovered in Advantech B+B SmartWorx MESR901 firmware versions 1.5.2 and prior. The web interface uses JavaScript to check client authentication and redirect unauthorized users. Attackers may intercept requests and bypass authentication to access restricted web pages.
0
Attacker Value
Unknown
CVE-2017-2096
Disclosure Date: April 28, 2017 (last updated November 26, 2024)
smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
0
Attacker Value
Unknown
CVE-2017-7628
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability).
0
Attacker Value
Unknown
CVE-2017-7627
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
The "Smart related articles" extension 1.1 for Joomla! does not prevent direct requests to dialog.php (there is a missing _JEXEC check).
0
Attacker Value
Unknown
CVE-2017-7626
Disclosure Date: April 13, 2017 (last updated November 26, 2024)
The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET Method).
0
Attacker Value
Unknown
CVE-2016-5682
Disclosure Date: April 10, 2017 (last updated November 26, 2024)
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
0