CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102758  CVE-2017-5938  Candidate  Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.  Assigned (20170208)  None (candidate not yet proposed)    View
87724  CVE-2016-10212  Candidate  Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270. NOTE: this issue may be due to the use of a third-party Cavium product.  Assigned (20170208)  None (candidate not yet proposed)    View
87725  CVE-2016-10213  Candidate  A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270.  Assigned (20170208)  None (candidate not yet proposed)    View
87726  CVE-2016-10214  Candidate  Memory leak in the virgl_resource_attach_backing function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.  Assigned (20170208)  None (candidate not yet proposed)    View
102713  CVE-2017-5893  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170207)  None (candidate not yet proposed)    View

Page 1015 of 20943, showing 5 records out of 104715 total, starting on record 5071, ending on 5075

Actions