Show filters
199 Total Results
Displaying 71-80 of 199
Sort by:
Attacker Value
Unknown

CVE-2019-15380

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Fly Photo Pro Android device with a build fingerprint of Fly/PhotoPro/Photo_Pro:8.1.0/O11019/1528117003:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
Attacker Value
Unknown

CVE-2015-9432

Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.
Attacker Value
Unknown

CVE-2018-14478

Disclosure Date: May 07, 2019 (last updated November 08, 2023)
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
0
Attacker Value
Unknown

CVE-2018-20371

Disclosure Date: December 23, 2018 (last updated November 27, 2024)
PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.
0
Attacker Value
Unknown

CVE-2018-3921

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A memory corruption vulnerability exists in the PSD-parsing functionality of Computerinsel Photoline 20.54. A specially crafted PSD image processed via the application can lead to a stack overflow, overwriting arbitrary data. An attacker can deliver a PSD image to trigger this vulnerability and gain code execution.
Attacker Value
Unknown

CVE-2018-3922

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A memory corruption vulnerability exists in the ANI-parsing functionality of Computerinsel Photoline 20.54. A specially crafted ANI image processed via the application can lead to a stack overflow, overwriting arbitrary data. An attacker can deliver an ANI image to trigger this vulnerability and gain code execution.
Attacker Value
Unknown

CVE-2018-3923

Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.54. A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.
Attacker Value
Unknown

CVE-2017-12107

Disclosure Date: April 24, 2018 (last updated November 26, 2024)
An memory corruption vulnerability exists in the .PCX parsing functionality of Computerinsel Photoline 20.02. A specially crafted .PCX file can cause a vulnerability resulting in potential code execution. An attacker can send a specific .PCX file to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2018-3861

Disclosure Date: April 12, 2018 (last updated November 26, 2024)
A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution.
Attacker Value
Unknown

CVE-2018-3862

Disclosure Date: April 12, 2018 (last updated November 26, 2024)
A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting