ECShop 4.1.0 has SQL injection vulnerability, which can be exploited by attackers to obtain sensitive information.Read More ...
Continue ReadingJune 28, 2022
DCMTK through 3.6.6 does not handle memory free properly. The program malloc a heap memory for parsing data, but does not free it when error in parsing. Sending specific requests to the dcmqrdb progra ...
Continue ReadingJune 28, 2022
DCMTK through 3.6.6 does not handle memory free properly. The object in the program is free but its address is still used in other locations. Sending specific requests to the dcmqrdb program will incu ...
Continue ReadingJune 28, 2022
DCMTK through 3.6.6 does not handle memory free properly. The malloced memory for storing all file information are recorded in a global variable LST and are not freed properly. Sending specific reques ...
Continue ReadingJune 28, 2022
Admidio 4.1.2 version is affected by stored cross-site scripting (XSS).Read More ...
Continue ReadingJune 28, 2022
Server-Side Request Forgery (SSRF) in GitHub repository dompdf/dompdf prior to 2.0.0.Read More ...
Continue ReadingJune 28, 2022
When an attacker obtaining the administrative account and password, or through a man-in-the-middle attack, the attacker could send a specified crafted packet to the vulnerable interface then lead the ...
Continue ReadingJune 28, 2022
Origin validation error vulnerability in NeoRSs ActiveX moudle allows attackers to download and execute arbitrary files. Remote attackers can use this vulerability to encourage users to access craft ...
Continue ReadingJune 28, 2022
Back to Main