Security Vulnerabilities
- CVEs Published In January 2020
Koala Framework before 2011-11-21 has XSS via the request_uri parameter.
Snare for Linux before 1.7.0 has password disclosure because the rendered page contains the field RemotePassword.
Snare for Linux before 1.7.0 has CSRF in the web interface.
Imperva SecureSphere Web Application Firewall (WAF) before 12-august-2010 allows SQL injection filter bypass.
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__find_table.
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_get8.
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in ttUSHORT.
stb stb_truetype.h through 1.22 has a heap-based buffer over-read in stbtt__buf_peek8.