Show filters
33 Total Results
Displaying 1-10 of 33
Sort by:
Attacker Value
Unknown
CVE-2023-43907
Disclosure Date: October 01, 2023 (last updated October 09, 2023)
OptiPNG v0.7.7 was discovered to contain a global buffer overflow via the 'buffer' variable at gifread.c.
0
Attacker Value
Unknown
CVE-2014-10067
Disclosure Date: May 29, 2018 (last updated November 26, 2024)
paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox. With a bit of time, an attacker could craft a request using the simulator that would fool any application which does not explicitly check for test_ipn in production.
0
Attacker Value
Unknown
CVE-2017-16938
Disclosure Date: November 24, 2017 (last updated November 26, 2024)
A global buffer overflow in OptiPNG 0.7.6 allows remote attackers to cause a denial-of-service attack or other unspecified impact with a maliciously crafted GIF format file, related to an uncontrolled loop in the LZWReadByte function of the gifread.c file.
0
Attacker Value
Unknown
CVE-2017-1000229
Disclosure Date: November 17, 2017 (last updated November 26, 2024)
Integer overflow bug in function minitiff_read_info() of optipng 0.7.6 allows an attacker to remotely execute code or cause denial of service.
0
Attacker Value
Unknown
CVE-2017-9606
Disclosure Date: June 15, 2017 (last updated November 26, 2024)
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction with a lack of integrity and authenticity checks.
0
Attacker Value
Unknown
CVE-2016-7831
Disclosure Date: June 09, 2017 (last updated November 26, 2024)
Sleipnir 4 Black Edition for Mac 4.5.3 and earlier and Sleipnir 4 for Mac 4.5.3 and earlier (Mac App Store) may allow a remote attacker to spoof the URL display via a specially crafted webpage.
0
Attacker Value
Unknown
CVE-2015-7802
Disclosure Date: April 20, 2016 (last updated November 25, 2024)
gifread.c in gif2png, as used in OptiPNG before 0.7.6, allows remote attackers to cause a denial of service (uninitialized memory read) via a crafted GIF file.
0
Attacker Value
Unknown
CVE-2015-7801
Disclosure Date: April 20, 2016 (last updated November 25, 2024)
Use-after-free vulnerability in OptiPNG 0.6.4 allows remote attackers to execute arbitrary code via a crafted PNG file.
0
Attacker Value
Unknown
CVE-2016-2191
Disclosure Date: April 13, 2016 (last updated November 25, 2024)
The bmp_read_rows function in pngxtern/pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (invalid memory write and crash) via a series of delta escapes in a crafted BMP image.
0
Attacker Value
Unknown
CVE-2016-3981
Disclosure Date: April 13, 2016 (last updated November 25, 2024)
Heap-based buffer overflow in the bmp_read_rows function in pngxrbmp.c in OptiPNG before 0.7.6 allows remote attackers to cause a denial of service (out-of-bounds read or write access and crash) or possibly execute arbitrary code via a crafted image file.
0