CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104215  CVE-2017-7395  Candidate  In TigerVNC 1.7.1 (SMsgReader.cxx SMsgReader::readClientCutText), by causing an integer overflow, an authenticated client can crash the server.  Assigned (20170331)  None (candidate not yet proposed)    View
104214  CVE-2017-7394  Candidate  In TigerVNC 1.7.1 (SSecurityPlain.cxx SSecurityPlain::processMsg), unauthenticated users can crash the server by sending long usernames.  Assigned (20170331)  None (candidate not yet proposed)    View
104213  CVE-2017-7393  Candidate  In TigerVNC 1.7.1 (VNCSConnectionST.cxx VNCSConnectionST::fence), an authenticated client can cause a double free, leading to denial of service or potentially code execution.  Assigned (20170331)  None (candidate not yet proposed)    View
104212  CVE-2017-7392  Candidate  In TigerVNC 1.7.1 (SSecurityVeNCrypt.cxx SSecurityVeNCrypt::SSecurityVeNCrypt), an unauthenticated client can cause a small memory leak in the server.  Assigned (20170331)  None (candidate not yet proposed)    View
104211  CVE-2017-7391  Candidate  A Cross-Site Scripting (XSS) was discovered in "Magmi 0.7.22". The vulnerability exists due to insufficient filtration of user-supplied data (prefix) passed to the "magmi-git-master/magmi/web/ajax_gettime.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170331)  None (candidate not yet proposed)    View

Page 101 of 20943, showing 5 records out of 104715 total, starting on record 501, ending on 505

Actions