|
265341
|
8.8 |
HIGH
Network
|
spip
|
spip
|
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag a…
|
CWE-20
Improper Input Validation
|
CVE-2016-7998
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265342
|
7.5 |
HIGH
Network
|
graphicsmagick
|
graphicsmagick
|
The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer.
|
CWE-476
NULL Pointer Dereference
|
CVE-2016-7997
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265343
|
9.8 |
CRITICAL
Network
|
graphicsmagick
|
graphicsmagick
|
Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7996
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265344
|
7.5 |
HIGH
Network
|
spip
|
spip
|
Directory traversal vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to enumerate the files on the system via the var_url parameter in a valider_xml acti…
|
CWE-22
Path Traversal
|
CVE-2016-7982
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265345
|
6.1 |
MEDIUM
Network
|
spip
|
spip
|
Cross-site scripting (XSS) vulnerability in valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the var_url parameter in a valider_xml action.
|
CWE-79
Cross-site Scripting
|
CVE-2016-7981
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265346
|
8.8 |
HIGH
Network
|
spip
|
spip
|
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that execu…
|
CWE-352
Origin Validation Error
|
CVE-2016-7980
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265347
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
magick/attribute.c in ImageMagick 7.0.3-2 allows remote attackers to cause a denial of service (use-after-free) via a crafted file.
|
CWE-416
Use After Free
|
CVE-2016-7906
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265348
|
6.5 |
MEDIUM
Network
|
imagemagick debian
|
imagemagick debian_linux
|
MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-7799
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265349
|
7.5 |
HIGH
Network
|
artifex
|
mujs
|
Heap-based buffer overflow in the Fp_toString function in jsfunction.c in Artifex Software MuJS allows attackers to cause a denial of service (crash) via crafted input.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-7564
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265350
|
7.5 |
HIGH
Network
|
artifex
|
mujs
|
The chartorune function in Artifex Software MuJS allows attackers to cause a denial of service (out-of-bounds read) via a * (asterisk) at the end of the input.
|
CWE-125
Out-of-bounds Read
|
CVE-2016-7563
|
2024-11-21 11:58 |
2017-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|