CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
94816 | CVE-2016-7996 | Candidate | Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94817 | CVE-2016-7997 | Candidate | The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (assertion failure and crash) via vectors related to a ReferenceBlob and a NULL pointer. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94818 | CVE-2016-7998 | Candidate | The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP code by uploading an HTML file with a crafted (1) INCLUDE or (2) INCLURE tag and then accessing it with a valider_xml action. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94819 | CVE-2016-7999 | Candidate | ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote attackers to conduct server side request forgery (SSRF) attacks via a URL in the var_url parameter in a valider_xml action. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94820 | CVE-2016-8000 | Candidate | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-0800. Reason: This candidate is a duplicate of CVE-2016-0800. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2016-0800 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | Assigned (20160302) | None (candidate not yet proposed) | View |
Page 18964 of 20943, showing 5 records out of 104715 total, starting on record 94816, ending on 94820