Unknown · CVSS Not scored
Other An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function updateusage() located in swftext.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function callcode() located in code.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_FontExtract_DefineFontInfo() located in swftext.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function FileStream::makeSubStream() located in Stream.cc. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_uint() located in pool.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function dump_method() located in abc.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function main() located in swfdump.c. It allows an attacker to cause code Execution.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_ReadABC() located in abc.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function traits_dump() located in abc.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D1() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function pool_lookup_string2() located in pool.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function code_parse() located in code.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function swf_GetPlaceObject() located in swfobject.c. It allows an attacker to cause code Execution.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function params_dump() located in abc.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A stack-buffer-overflow exists in the function rfx_alloc() located in mem.c. It allows an attacker to cause code Execution.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpABC() located in abc.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_DumpActions() located in swfaction.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function swf_GetShapeBoundingBox() located in swfshape.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function InfoOutputDev::type3D0() located in InfoOutputDev.cc. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A heap-buffer-overflow exists in the function OpAdvance() located in swfaction.c. It allows an attacker to cause code Execution.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function copyString() located in gmem.cc. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function GString::~GString() located in GString.cc. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Font::Size() located in font.cpp. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Eyoucms 1.5.4 is vulnerable to Directory Traversal. Due to a lack of input data sanitizaton in param tpldir, filename, type, nid an attacker can inject "../" to escape and write file to writeable directories.
Published Sep 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function Analyze::AnalyzeXref() located in analyze.cpp. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a stack-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in swftools through 20200710. A NULL pointer dereference exists in the function Lexer::Lexer() located in Lexer.cc. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in sela through 20200412. rice::RiceDecoder::process() in rice_decoder.cpp has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
EyouCMS 1.5.4 is vulnerable to Open Redirect. An attacker can redirect a user to a malicious url via the Logout function.
Published Sep 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in sela through 20200412. file::SelaFile::readFromFile() in sela_file.cpp has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in libslax through v0.22.1. slaxIsCommentStart() in slaxlexer.c has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in sela through 20200412. file::SelaFile::readFromFile() in sela_file.c has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in ncurses through v6.2-1. _nc_captoinfo in captoinfo.c has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
PHPMyWind 5.6 is vulnerable to Remote Code Execution. Becase input is filtered without "<, >, ?, =, `,...." In WriteConfig() function, an attacker can inject php code to /include/config.cache.php file.
Published Sep 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in libredwg through v0.10.1.3751. appinfo_private() in decode.c has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in libjpeg through 2020021. A NULL pointer dereference exists in the function BlockBitmapRequester::PullQData() located in blockbitmaprequester.cpp It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in pdftools through 20200714. A NULL pointer dereference exists in the function node::ObjNode::Value() located in objnode.cpp. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in libjpeg through 2020021. LineBuffer::FetchRegion() in linebuffer.cpp has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in libredwg through v0.10.1.3751. A NULL pointer dereference exists in the function bit_read_BB() located in bits.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in libslax through v0.22.1. slaxLexer() in slaxlexer.c has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Samsung Drive Manager 2.0.104 on Samsung H3 devices allows attackers to bypass intended access controls on disk management. WideCharToMultiByte, WideCharStr, and MultiByteStr can contribute to password exposure.
Published Sep 1, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
MaianAffiliate v.1.0 is suffers from code injection by adding a new product via the admin panel. The injected payload is reflected on the affiliate main page for all authenticated and unauthenticated visitors.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
Remote code execution in the modules component in Yakamara Media Redaxo CMS version 5.12.1 allows an authenticated CMS user to execute code on the hosting system via a module containing malicious PHP code.
Published Sep 9, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
eyoucms 1.5.4 lacks sanitization of input data, allowing an attacker to inject a url to trigger blind SSRF via the saveRemote() function.
Published Sep 7, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in sela through 20200412. file::WavFile::readFromFile() in wav_file.c has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function file::WavFile::WavFile() located in wav_file.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2len() in bits.c has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in sela through 20200412. A NULL pointer dereference exists in the function rice::RiceDecoder::process() located in rice_decoder.c. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in libredwg through v0.10.1.3751. bit_wcs2nlen() in bits.c has a heap-based buffer overflow.
Published Sep 20, 2021 · Updated Aug 4, 2024
Unknown · CVSS Not scored
An issue was discovered in libxsmm through v1.16.1-93. A NULL pointer dereference exists in JIT code. It allows an attacker to cause Denial of Service.
Published Sep 20, 2021 · Updated Aug 4, 2024