CVE-2020-6069
https://notcve.org/view.php?id=CVE-2020-6069
11 Feb 2020 — An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll JPEG jpegread precision parser of the Accusoft ImageGear 19.5.0 library. A specially crafted JPEG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability. Se presenta una vulnerabilidad de escritura fuera de límites explotable en el analizador de precisión JPEG jpegread de la biblioteca igcore19d.dll de Accusoft ImageGear v... • https://talosintelligence.com/vulnerability_reports/TALOS-2020-0993 • CWE-787: Out-of-bounds Write •
CVE-2020-6064
https://notcve.org/view.php?id=CVE-2020-6064
11 Feb 2020 — An exploitable out-of-bounds write vulnerability exists in the uncompress_scan_line function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted PCX file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability. Se presenta una vulnerabilidad de escritura fuera de límites explotable en la función uncompress_scan_line de la biblioteca igcore19d.dll de Accusoft ImageGear,... • https://talosintelligence.com/vulnerability_reports/TALOS-2020-0987 • CWE-787: Out-of-bounds Write •
CVE-2020-6065
https://notcve.org/view.php?id=CVE-2020-6065
11 Feb 2020 — An exploitable out-of-bounds write vulnerability exists in the bmp_parsing function of the igcore19d.dll library of Accusoft ImageGear, version 19.5.0. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability. Se presenta una vulnerabilidad de escritura fuera de límites explotable en la función bmp_parsing de la biblioteca igcore19d.dll de Accusoft ImageGear, versión 19.5.0. U... • https://talosintelligence.com/vulnerability_reports/TALOS-2020-0989 • CWE-787: Out-of-bounds Write •
CVE-2019-5133
https://notcve.org/view.php?id=CVE-2019-5133
03 Dec 2019 — An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll BMP parser of the ImageGear 19.3.0 library. A specially crafted BMP file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability. Existe una vulnerabilidad de escritura fuera de límites explotable en el analizador BMP de igcore19d.dll de la biblioteca ImageGear versión 19.3.0. Un archivo BMP especialmente diseñado puede causar u... • https://talosintelligence.com/vulnerability_reports/TALOS-2019-0922 • CWE-787: Out-of-bounds Write •
CVE-2019-5132
https://notcve.org/view.php?id=CVE-2019-5132
03 Dec 2019 — An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll GEM Raster parser of the Accusoft ImageGear 19.3.0 library. A specially crafted GEM file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability. Existe una vulnerabilidad de escritura fuera de límites explotable en el analizador de GEM Raster de igcore19d.dll de la biblioteca Accusoft ImageGear versión 19.3.0. Un archivo GEM es... • https://talosintelligence.com/vulnerability_reports/TALOS-2019-0921 • CWE-787: Out-of-bounds Write •
CVE-2019-5076
https://notcve.org/view.php?id=CVE-2019-5076
03 Dec 2019 — An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll PNG header-parser of the Accusoft ImageGear 19.3.0 library. A specially crafted PNG file can cause an out-of-bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the viction to trigger the vulnerability. Se presenta una vulnerabilidad de escritura fuera de límites explotable en el analizador de encabezado PNG de igcore19d.dll de la biblioteca Accusoft ImageGear versión 19.3.0. Un arch... • https://talosintelligence.com/vulnerability_reports/TALOS-2019-0865 • CWE-787: Out-of-bounds Write •
CVE-2019-5083
https://notcve.org/view.php?id=CVE-2019-5083
03 Dec 2019 — An exploitable out-of-bounds write vulnerability exists in the igcore19d.dll TIFdecodethunderscan function of Accusoft ImageGear 19.3.0 library. A specially crafted TIFF file can cause an out of bounds write, resulting in a remote code execution. An attacker needs to provide a malformed file to the victim to trigger the vulnerability. Se presenta una vulnerabilidad de escritura fuera de límites explotable en la función TIFdecodethunderscan de igcore19d.dll de la biblioteca Accusoft ImageGear versión 19.3.0.... • https://talosintelligence.com/vulnerability_reports/TALOS-2019-0875 • CWE-787: Out-of-bounds Write •
CVE-2018-15805
https://notcve.org/view.php?id=CVE-2018-15805
10 Dec 2018 — Accusoft PrizmDoc HTML5 Document Viewer before 13.5 contains an XML external entity (XXE) vulnerability, allowing an attacker to read arbitrary files or cause a denial of service (resource consumption). En ParsePayloadHeader de payload_metadata.cc, hay una posible escritura fuera de límites debido a un desbordamiento de enteros. Esto podría llevar a un escalado de privilegios remoto sin necesitar privilegios de ejecución adicionales. No se necesita interacción del usuario para explotarlo. Producto: Android.... • https://help.accusoft.com/PrizmDoc/v13.5/HTML/webframe.html#Release_v13_5.html • CWE-611: Improper Restriction of XML External Entity Reference •
CVE-2018-15546
https://notcve.org/view.php?id=CVE-2018-15546
18 Sep 2018 — Accusoft PrizmDoc version 13.3 and earlier contains a Stored Cross-Site Scripting issue through a crafted PDF file. Accusoft PrizmDoc en versiones 13.3 y anteriores contiene un problema de Cross-Site Scripting (XSS) persistente mediante un archivo PDF manipulado. • http://help.accusoft.com/PrizmDoc/v13.4/ReleaseNotes/index.htm • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2012-5190 – Prizm Content Connect - Arbitrary File Upload
https://notcve.org/view.php?id=CVE-2012-5190
11 Jan 2013 — Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability Prizm Content Connect versión 5.1, presenta una Vulnerabilidad de Carga de Archivos Arbitraria. Prizm Content Connect version 5.1 suffers from a remote download and code execution vulnerability. • https://www.exploit-db.com/exploits/38204 • CWE-434: Unrestricted Upload of File with Dangerous Type •