|
251461
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer over-read in read_creator_block in plug-ins/common/file-psp.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17787
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251462
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer over-read in ReadImage in plug-ins/common/file-tga.c (related to bgr2rgb.part.1) via an unexpected bits-per-pixel value for an RGBA image.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17786
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251463
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer overflow in the fli_read_brun function in plug-ins/file-fli/fli.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2017-17785
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251464
|
7.8 |
HIGH
Local
|
gimp debian canonical
|
gimp debian_linux ubuntu_linux
|
In GIMP 2.8.22, there is a heap-based buffer over-read in load_image in plug-ins/common/file-gbr.c in the gbr import parser, related to mishandling of UTF-8 data.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17784
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251465
|
7.5 |
HIGH
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17783
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251466
|
8.8 |
HIGH
Network
|
graphicsmagick debian
|
graphicsmagick debian_linux
|
In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation.
|
CWE-125
Out-of-bounds Read
|
CVE-2017-17782
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251467
|
9.8 |
CRITICAL
Network
|
paid_to_read_script_project
|
paid_to_read_script
|
Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.
|
CWE-89
SQL Injection
|
CVE-2017-17779
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251468
|
4.8 |
MEDIUM
Network
|
paid_to_read_script_project
|
paid_to_read_script
|
Paid To Read Script 2.0.5 has XSS via the referrals.php tier parameter or the admin/userview.php uid parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17778
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251469
|
9.8 |
CRITICAL
Network
|
paid_to_read_script_project
|
paid_to_read_script
|
Paid To Read Script 2.0.5 has authentication bypass in the admin panel via a direct request, as demonstrated by the admin/viewvisitcamp.php fn parameter and the admin/userview.php uid parameter.
|
CWE-287
Improper Authentication
|
CVE-2017-17777
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251470
|
5.3 |
MEDIUM
Network
|
paid_to_read_script_project
|
paid_to_read_script
|
Paid To Read Script 2.0.5 has full path disclosure via an invalid admin/userview.php uid parameter.
|
CWE-200
Information Exposure
|
CVE-2017-17776
|
2024-11-21 12:18 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|