Show filters
732 Total Results
Displaying 541-550 of 732
Sort by:
Attacker Value
Unknown

CVE-2016-5241

Disclosure Date: February 03, 2017 (last updated November 25, 2024)
magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file.
0
Attacker Value
Unknown

CVE-2016-7997

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer.
0
Attacker Value
Unknown

CVE-2016-7996

Disclosure Date: January 18, 2017 (last updated November 25, 2024)
Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries.
0
Attacker Value
Unknown

CVE-2016-7904

Disclosure Date: January 16, 2017 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrators for requests that create accounts via an admin/adduser.php request.
0
Attacker Value
Unknown

CVE-2015-8808

Disclosure Date: July 13, 2016 (last updated November 25, 2024)
The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file.
0
Attacker Value
Unknown

CVE-2016-5118

Disclosure Date: June 10, 2016 (last updated November 20, 2024)
The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.
Attacker Value
Unknown

CVE-2016-2784

Disclosure Date: May 26, 2016 (last updated November 25, 2024)
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.
0
Attacker Value
Unknown

CVE-2015-6484

Disclosure Date: October 25, 2015 (last updated October 05, 2023)
3S-Smart CODESYS Gateway Server before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted (1) GET or (2) POST request.
0
Attacker Value
Unknown

CVE-2015-6460

Disclosure Date: September 18, 2015 (last updated October 05, 2023)
Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote attackers to execute arbitrary code via opcode (1) 0x3ef or (2) 0x3f0.
0
Attacker Value
Unknown

CVE-2015-3964

Disclosure Date: September 11, 2015 (last updated October 05, 2023)
SMA Solar Sunny WebBox has hardcoded passwords, which makes it easier for remote attackers to obtain access via unspecified vectors.
0