CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102435  CVE-2017-5615  Candidate  cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.  Assigned (20170128)  None (candidate not yet proposed)    View
102436  CVE-2017-5616  Candidate  Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum parameter.  Assigned (20170128)  None (candidate not yet proposed)    View
87673  CVE-2016-10166  Candidate  Integer underflow in the _gdContributionsAlloc function in gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors related to decrementing the u variable.  Assigned (20170128)  None (candidate not yet proposed)    View
87674  CVE-2016-10167  Candidate  The gdImageCreateFromGd2Ctx function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted image file.  Assigned (20170128)  None (candidate not yet proposed)    View
87675  CVE-2016-10168  Candidate  Integer overflow in gd_io.c in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to have unspecified impact via vectors involving the number of horizontal and vertical chunks in an image.  Assigned (20170128)  None (candidate not yet proposed)    View

Page 19856 of 20943, showing 5 records out of 104715 total, starting on record 99276, ending on 99280

Actions