All CVEs — page 227 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows for potential out-of-bounds memory access due to improper validation of offset parameters in the crop function, which could lead to arbitrary code execution if exploited.
The flaw allows a negative ratio to cause image processing functions to fail, potentially crashing the application due to invalid width values.
The flaw allows remote code execution by manipulating the ratio parameter in imagecli's pipeline operation without proper validation, leading to potential crashes or arbitrary code execution.
The flaw in Pluck CMS's admin panel allows attackers to perform cross-site request forgery (CSRF) attacks by manipulating the Referer header, leading to potential unauthorized actions.
The flaw allows unauthenticated attackers to access sensitive information such as API keys and task parameters through the `getCurrentTaskResults()` method in the AIWU plugin for WordPress.
The flaw allows unauthenticated attackers to modify or delete Stripe payment credentials, enabling credential theft or account takeover.
The LightSync Pro plugin for WordPress allows attackers to upload arbitrary files due to missing file type validation, posing a risk of remote code execution for users with Author-level access or higher.
The flaw allows unauthenticated attackers to modify and access data through missing capability checks in the Material Dashboard plugin for WordPress.
The flaw allows arbitrary function execution via an unfiltered user input parameter, enabling authenticated attackers with Administrator-level access to run any PHP code.
The vulnerability in xfrm_user_policy() allows for a double-free condition in sk_dst_cache, leading to potential kernel crashes or exploits if exploited.
The vulnerability in xfrm6_fill_dst() allows for a double netdev_put(), potentially leading to a use-after-free condition and refcount underflow.
This flaw allows a remote client to read out-of-bounds data by crafting a compound SMB2 request with an improperly sized StructureSize2 field, potentially leading to information disclosure.
This vulnerability in the Linux kernel's GTP (Generic Tunneling Protocol) implementation allows a malicious packet with specific payload to cause a kernel panic by triggering an invalid memory access.
The flaw is a potential general protection fault due to uninitialized netlink_ext_ack pointer dereferencing in the Linux kernel's nexthop module. This matters because it could lead to a kernel panic or system instability if exploited.
The vulnerability allows for a null pointer dereference in the Linux kernel's bpf_iter_tcp_batch function, which can lead to potential system instability or crashes.
The flaw involves a use-after-free vulnerability in the Linux kernel's mac80211 subsystem when adding new links during vif update. This can lead to dereferencing freed memory via debugfs files.
The vulnerability involves a double-free issue in the Linux kernel's mac80211 module when handling Fils Discovery, leading to potential memory corruption.