NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
82120 | CVE-2016-9553 | The Sophos Web Appliance (version 4.2.1.3) is vulnerable to two Remote Command Injection vulnerabilities affecting its web administrative interface. These vulnerabilities occur in the MgrReport.php (/controllers/MgrReport.php) component responsible for blocking and unblocking IP addresses from accessing the device. The device doesn"t properly escape the information passed in the variables "unblockip" and "blockip" before calling the shell_exec() function which allows for system commands to be injected into the device. The code erroneously suggests that the information handled is protected by utilizing the variable name "escapedips" - however this was not the case. The Sophos ID is NSWA-1258. | 2017-02-28 | 2017-02-23 | View | ||||
82119 | CVE-2016-9453 | The t2p_readwrite_pdf_image_tile function in LibTIFF allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a JPEG file with a TIFFTAG_JPEGTABLES of length one. | 2 | 6.8 | Medium | 2017-02-08 | 2017-02-07 | View | |
82118 | CVE-2016-9448 | The TIFFFetchNormalTag function in LibTiff 4.0.6 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by setting the tags TIFF_SETGET_C16ASCII or TIFF_SETGET_C32_ASCII to values that access 0-byte arrays. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-9297. | 2 | 5 | Medium | 2017-02-08 | 2017-02-07 | View | |
82117 | CVE-2016-9317 | The gdImageCreate function in the GD Graphics Library (aka libgd) before 2.2.4 allows remote attackers to cause a denial of service (system hang) via an oversized image. | 2 | 7.1 | High | 2017-02-08 | 2017-01-31 | View | |
82116 | CVE-2016-9298 | Heap overflow in the WaveletDenoiseImage function in MagickCore/fx.c in ImageMagick before 6.9.6-4 and 7.x before 7.0.3-6 allows remote attackers to cause a denial of service (crash) via a crafted image. | 2 | 4.3 | Medium | 2017-02-08 | 2017-02-07 | View |
Page 1249 of 17672, showing 5 records out of 88360 total, starting on record 6241, ending on 6245