[webapps] – ManageEngine Firewall Analyzer 8.5 – Multiple Vulnerabilities
Posted by deepcore under Security (No Respond)
The Vulnerability Laboratory Core Research Team discovered an application-side input validation web vulnerability in the official ifixit online service web-application.
Dimofinf CMS version 3.0.0 suffers from a cross site scripting vulnerability.
The included fuzzing test case causes a crash due to a heap overflow in BitmapData.drawWithQuality.
The attached file can cause an out-of-bounds read of an image. While the bits of the image are null, the width, height and other values can make it a valid pointer.