Show filters
133 Total Results
Displaying 91-100 of 133
Sort by:
Attacker Value
Unknown

CVE-2012-1798

Disclosure Date: June 05, 2012 (last updated October 04, 2023)
The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF image.
Attacker Value
Unknown

CVE-2012-0260

Disclosure Date: June 05, 2012 (last updated October 04, 2023)
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
Attacker Value
Unknown

CVE-2012-0248

Disclosure Date: June 05, 2012 (last updated October 04, 2023)
ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.
Attacker Value
Unknown

CVE-2012-1097

Disclosure Date: May 17, 2012 (last updated November 24, 2024)
The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call.
Attacker Value
Unknown

CVE-2012-1090

Disclosure Date: May 17, 2012 (last updated November 24, 2024)
The cifs_lookup function in fs/cifs/dir.c in the Linux kernel before 3.2.10 allows local users to cause a denial of service (OOPS) via attempted access to a special file, as demonstrated by a FIFO.
Attacker Value
Unknown

CVE-2012-1823

Disclosure Date: May 11, 2012 (last updated July 17, 2024)
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.
Attacker Value
Unknown

CVE-2011-3045

Disclosure Date: March 22, 2012 (last updated October 04, 2023)
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
0
Attacker Value
Unknown

CVE-2012-0053

Disclosure Date: January 28, 2012 (last updated October 04, 2023)
protocol.c in the Apache HTTP Server 2.2.x through 2.2.21 does not properly restrict header information during construction of Bad Request (aka 400) error documents, which allows remote attackers to obtain the values of HTTPOnly cookies via vectors involving a (1) long or (2) malformed header in conjunction with crafted web script.
0
Attacker Value
Unknown

CVE-2012-0031

Disclosure Date: January 18, 2012 (last updated October 04, 2023)
scoreboard.c in the Apache HTTP Server 2.2.21 and earlier might allow local users to cause a denial of service (daemon crash during shutdown) or possibly have unspecified other impact by modifying a certain type field within a scoreboard shared memory segment, leading to an invalid call to the free function.
0
Attacker Value
Unknown

CVE-2009-3289

Disclosure Date: September 22, 2009 (last updated February 09, 2024)
The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.