** DISPUTED ** In the GD Graphics Library (aka LibGD) through 2.2.5, there is a heap-based buffer over-read in tiffWriter in gd_tiff.c. NOTE: the vendor says "In my opinion this issue should not have a CVE, since the GD and GD2 formats are documented to be ‘obsolete, and should only be used for development and testing purposes.’"
View Full Alert
Related Posts
CVE-2017-12652libpng before 1.6.32 does not properly check the length of chunks against the user limit. View Full Alert
CVE-2017-18615The kama-clic-counter plugin before 3.5.0 for WordPress has XSS. View Full Alert
CVE-2017-18636CDG through 2017-01-01 allows downloadDocument.jsp?command=download&pathAndName= directory traversal. View Full Alert