|
208201
|
3.3 |
LOW
Local
|
imagemagick redhat debian
|
imagemagick enterprise_linux debian_linux
|
A flaw was found in ImageMagick in MagickCore/gem-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the…
|
CWE-369
Divide By Zero
|
CVE-2020-27773
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208202
|
3.3 |
LOW
Local
|
imagemagick redhat debian
|
imagemagick enterprise_linux debian_linux
|
A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of ty…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27772
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208203
|
3.3 |
LOW
Local
|
imagemagick redhat
|
imagemagick enterprise_linux
|
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the r…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27776
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208204
|
3.3 |
LOW
Local
|
imagemagick redhat debian
|
imagemagick enterprise_linux debian_linux
|
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the ran…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27775
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208205
|
3.3 |
LOW
Local
|
imagemagick redhat debian
|
imagemagick enterprise_linux debian_linux
|
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of a too large shift fo…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27774
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208206
|
6.1 |
MEDIUM
Network
|
os4ed
|
opensis
|
OpenSIS Community Edition before 7.5 is affected by a cross-site scripting (XSS) vulnerability in SideForStudent.php via the modname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2020-27409
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208207
|
7.5 |
HIGH
Network
|
os4ed
|
opensis
|
OpenSIS Community Edition through 7.6 is affected by incorrect access controls for the file ResetUserInfo.php that allow an unauthenticated attacker to change the password of arbitrary users.
|
CWE-287 CWE-640
Improper Authentication Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2020-27408
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208208
|
3.3 |
LOW
Local
|
imagemagick redhat debian
|
imagemagick enterprise_linux debian_linux
|
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values outside the range of representable for the unsigned char type. The patch casts th…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27771
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208209
|
5.5 |
MEDIUM
Local
|
imagemagick debian
|
imagemagick debian_linux
|
Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27770
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208210
|
7.8 |
HIGH
Local
|
imagemagick debian
|
imagemagick debian_linux
|
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the r…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2020-27766
|
2024-11-21 14:21 |
2020-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|