|
264551
|
9.8 |
CRITICAL
Network
|
graphicsmagick
|
graphicsmagick
|
Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7996
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264552
|
7.5 |
HIGH
Network
|
spip
|
spip
|
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml acti…
|
CWE-22
Path Traversal
|
CVE-2016-7982
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264553
|
6.1 |
MEDIUM
Network
|
spip
|
spip
|
Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.
|
CWE-79
Cross-site Scripting
|
CVE-2016-7981
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264554
|
8.8 |
HIGH
Network
|
spip
|
spip
|
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execu…
|
CWE-352
Origin Validation Error
|
CVE-2016-7980
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264555
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.
|
CWE-416
Use After Free
|
CVE-2016-7906
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264556
|
6.5 |
MEDIUM
Network
|
imagemagick debian
|
imagemagick debian_linux
|
MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-7799
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264557
|
7.5 |
HIGH
Network
|
artifex
|
mujs
|
Heap-based buffer overflow in the Fp_toString function in jsfunction.c in Artifex Software MuJS allows attackers to cause a denial of service (crash) via crafted input.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7564
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264558
|
7.5 |
HIGH
Network
|
artifex
|
mujs
|
The chartorune function in Artifex Software MuJS allows attackers to cause a denial of service (out-of-bounds read) via a * (asterisk) at the end of the input.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-7563
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264559
|
8.0 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
Cross-site request forgery (CSRF) vulnerability in CMS Made Simple before 2.1.6 allows remote attackers to hijack the authentication of administrators for requests that create accounts via an admin/a…
|
CWE-352
Origin Validation Error
|
CVE-2016-7904
|
2024-11-21 11:58 |
2017-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264560
|
7.5 |
HIGH
Network
|
brocade
|
network_advisor
|
A Directory Traversal vulnerability in CliMonitorReportServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to read arbitrary files incl…
|
CWE-22
Path Traversal
|
CVE-2016-8207
|
2024-11-21 11:58 |
2017-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|