CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94816  CVE-2016-7996  Candidate  Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries.  Assigned (20160909)  None (candidate not yet proposed)    View
94817  CVE-2016-7997  Candidate  The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer.  Assigned (20160909)  None (candidate not yet proposed)    View
94818  CVE-2016-7998  Candidate  The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action.  Assigned (20160909)  None (candidate not yet proposed)    View
94819  CVE-2016-7999  Candidate  ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action.  Assigned (20160909)  None (candidate not yet proposed)    View
94820  CVE-2016-8000  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0800. Reason: This candidate is a duplicate of CVE-2016-0800. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2016-0800 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20160302)  None (candidate not yet proposed)    View

Page 18964 of 20943, showing 5 records out of 104715 total, starting on record 94816, ending on 94820

Actions