Show filters
199 Total Results
Displaying 71-80 of 199
Sort by:
Attacker Value
Unknown
CVE-2019-15380
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The Fly Photo Pro Android device with a build fingerprint of Fly/PhotoPro/Photo_Pro:8.1.0/O11019/1528117003:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property through an exported interface without proper authorization.
0
Attacker Value
Unknown
CVE-2015-9432
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
The alpine-photo-tile-for-instagram plugin before 1.2.7.6 for WordPress has CSRF with resultant XSS via the wp-admin/options-general.php?page=alpine-photo-tile-for-instagram-settings tab parameter.
0
Attacker Value
Unknown
CVE-2018-14478
Disclosure Date: May 07, 2019 (last updated November 08, 2023)
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
0
Attacker Value
Unknown
CVE-2018-20371
Disclosure Date: December 23, 2018 (last updated November 27, 2024)
PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.
0
Attacker Value
Unknown
CVE-2018-3921
Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A memory corruption vulnerability exists in the PSD-parsing functionality of Computerinsel Photoline 20.54. A specially crafted PSD image processed via the application can lead to a stack overflow, overwriting arbitrary data. An attacker can deliver a PSD image to trigger this vulnerability and gain code execution.
0
Attacker Value
Unknown
CVE-2018-3922
Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A memory corruption vulnerability exists in the ANI-parsing functionality of Computerinsel Photoline 20.54. A specially crafted ANI image processed via the application can lead to a stack overflow, overwriting arbitrary data. An attacker can deliver an ANI image to trigger this vulnerability and gain code execution.
0
Attacker Value
Unknown
CVE-2018-3923
Disclosure Date: August 01, 2018 (last updated November 27, 2024)
A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.54. A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.
0
Attacker Value
Unknown
CVE-2017-12107
Disclosure Date: April 24, 2018 (last updated November 26, 2024)
An memory corruption vulnerability exists in the .PCX parsing functionality of Computerinsel Photoline 20.02. A specially crafted .PCX file can cause a vulnerability resulting in potential code execution. An attacker can send a specific .PCX file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-3861
Disclosure Date: April 12, 2018 (last updated November 26, 2024)
A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution.
0
Attacker Value
Unknown
CVE-2018-3862
Disclosure Date: April 12, 2018 (last updated November 26, 2024)
A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting
0