Show filters
268 Total Results
Displaying 71-80 of 268
Sort by:
Attacker Value
Unknown

CVE-2021-43562

Disclosure Date: November 10, 2021 (last updated February 23, 2025)
An issue was discovered in the pixxio (aka pixx.io integration or DAM) extension before 1.0.6 for TYPO3. The extension fails to restrict the image download to the configured pixx.io DAM URL, resulting in SSRF. As a result, an attacker can download various content from a remote location and save it to a user-controlled filename, which may result in Remote Code Execution. A TYPO3 backend user account is required to exploit this.
Attacker Value
Unknown

CVE-2021-29056

Disclosure Date: August 17, 2021 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability exists in Pixelimity 1.0 via the HTTP POST parameter to admin/setting.php.
Attacker Value
Unknown

CVE-2021-38085

Disclosure Date: August 11, 2021 (last updated February 23, 2025)
The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if timed properly, the overwritten DLL will be loaded into a SYSTEM process resulting in escalation of privileges. This occurs because the driver drops a world-writable DLL into a CanonBJ %PROGRAMDATA% location that gets loaded by printisolationhost (a system process).
Attacker Value
Unknown

CVE-2021-20240

Disclosure Date: May 28, 2021 (last updated February 22, 2025)
A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Attacker Value
Unknown

CVE-2020-23522

Disclosure Date: January 19, 2021 (last updated February 22, 2025)
Pixelimity 1.0 has cross-site request forgery via the admin/setting.php data [Password] parameter.
Attacker Value
Unknown

CVE-2020-29385

Disclosure Date: December 26, 2020 (last updated February 22, 2025)
GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the value of 10. This will make the loop run infinitely. This bug can, for example, be triggered by calling this function with a GIF image with LZW compression that is crafted in a special way.
Attacker Value
Unknown

CVE-2020-7640

Disclosure Date: April 27, 2020 (last updated February 21, 2025)
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
Attacker Value
Unknown

CVE-2019-20326

Disclosure Date: March 16, 2020 (last updated February 21, 2025)
A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and potentially execute arbitrary code via a crafted JPEG file.
Attacker Value
Unknown

CVE-2020-10257

Disclosure Date: March 10, 2020 (last updated February 21, 2025)
The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-api.php calls trx_addons_rest_get_sc_layout with an unsafe sc parameter.
Attacker Value
Unknown

CVE-2013-3486

Disclosure Date: January 27, 2020 (last updated February 21, 2025)
IrfanView FlashPix Plugin 4.3.4 0 has an Integer Overflow Vulnerability