CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102805  CVE-2017-5985  Candidate  lxc-user-nic in Linux Containers (LXC) allows local users with a lxc-usernet allocation to create network interfaces on the host and choose the name of those interfaces by leveraging lack of netns ownership check.  Assigned (20170213)  None (candidate not yet proposed)    View
102789  CVE-2017-5969  Candidate  ** DISPUTED ** libxml2 2.9.4, when used in recover mode, allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted XML document. NOTE: The maintainer states "I would disagree of a CVE with the Recover parsing option which should only be used for manual recovery at least for XML parser."  Assigned (20170212)  None (candidate not yet proposed)    View
102790  CVE-2017-5970  Candidate  The ipv4_pktinfo_prepare function in net/ipv4/ip_sockglue.c in the Linux kernel through 4.9.9 allows attackers to cause a denial of service (system crash) via (1) an application that makes crafted system calls or possibly (2) IPv4 traffic with invalid IP options.  Assigned (20170212)  None (candidate not yet proposed)    View
102791  CVE-2017-5971  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170212)  None (candidate not yet proposed)    View
102792  CVE-2017-5972  Candidate  The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many TCP SYN packets, as demonstrated by an attack against the kernel-3.10.0 package in CentOS Linux 7.  Assigned (20170212)  None (candidate not yet proposed)    View

Page 1005 of 20943, showing 5 records out of 104715 total, starting on record 5021, ending on 5025

Actions