|
255371
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.6-5, a length-validation vulnerability was found in the function ReadPSDLayersInternal in coders/psd.c, which allows attackers to cause a denial of service (ReadPSDImage memory exh…
|
CWE-20
Improper Input Validation
|
CVE-2017-13061
|
2024-11-21 12:10 |
2017-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255372
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.6-5, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-13060
|
2024-11-21 12:10 |
2017-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255373
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function WriteOneJNGImage in coders/png.c, which allows attackers to cause a denial of service (WriteJNGImage memory consumption) …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-13059
|
2024-11-21 12:10 |
2017-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255374
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function WritePCXImage in coders/pcx.c, which allows attackers to cause a denial of service via a crafted file.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2017-13058
|
2024-11-21 12:10 |
2017-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255375
|
6.1 |
MEDIUM
Network
|
phpmywind
|
phpmywind
|
PHPMyWind 5.3 has XSS in shoppingcart.php, related to message.php, admin/message.php, and admin/message_update.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12984
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255376
|
8.8 |
HIGH
Network
|
imagemagick
|
imagemagick
|
Heap-based buffer overflow in the ReadSFWImage function in coders/sfw.c in ImageMagick 7.0.6-8 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ot…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12983
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255377
|
5.5 |
MEDIUM
Local
|
uclouvain
|
openjpeg
|
The bmp_read_info_header function in bin/jp2/convertbmp.c in OpenJPEG 2.2.0 does not reject headers with a zero biBitCount, which allows remote attackers to cause a denial of service (memory allocati…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-12982
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255378
|
9.8 |
CRITICAL
Network
|
nexusphp
|
nexusphp
|
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.
|
CWE-89
SQL Injection
|
CVE-2017-12981
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255379
|
6.1 |
MEDIUM
Network
|
dokuwiki
|
dokuwiki
|
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious RSS or Atom feed, in /inc/parser/xhtml.php. An attacker can create or edit a wiki that uses RSS or Atom data from an attacker-co…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12980
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255380
|
6.1 |
MEDIUM
Network
|
dokuwiki
|
dokuwiki
|
DokuWiki through 2017-02-19c has stored XSS when rendering a malicious language name in a code element, in /inc/parser/xhtml.php. An attacker can create or edit a wiki with this element to trigger Ja…
|
CWE-79
Cross-site Scripting
|
CVE-2017-12979
|
2024-11-21 12:10 |
2017-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|