CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102758 | CVE-2017-5938 | Candidate | Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name. | Assigned (20170208) | None (candidate not yet proposed) | View | |
87724 | CVE-2016-10212 | Candidate | Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270. NOTE: this issue may be due to the use of a third-party Cavium product. | Assigned (20170208) | None (candidate not yet proposed) | View | |
87725 | CVE-2016-10213 | Candidate | A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270. | Assigned (20170208) | None (candidate not yet proposed) | View | |
87726 | CVE-2016-10214 | Candidate | Memory leak in the virgl_resource_attach_backing function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands. | Assigned (20170208) | None (candidate not yet proposed) | View | |
102713 | CVE-2017-5893 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170207) | None (candidate not yet proposed) | View |
Page 1015 of 20943, showing 5 records out of 104715 total, starting on record 5071, ending on 5075