CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102435 | CVE-2017-5615 | Candidate | cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location. | Assigned (20170128) | None (candidate not yet proposed) | View | |
102436 | CVE-2017-5616 | Candidate | Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter. | Assigned (20170128) | None (candidate not yet proposed) | View | |
87673 | CVE-2016-10166 | Candidate | Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable. | Assigned (20170128) | None (candidate not yet proposed) | View | |
87674 | CVE-2016-10167 | Candidate | The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file. | Assigned (20170128) | None (candidate not yet proposed) | View | |
87675 | CVE-2016-10168 | Candidate | Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image. | Assigned (20170128) | None (candidate not yet proposed) | View |
Page 19856 of 20943, showing 5 records out of 104715 total, starting on record 99276, ending on 99280