CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102744  CVE-2017-5924  Candidate  libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_compiler_destroy function.  Assigned (20170207)  None (candidate not yet proposed)    View
102745  CVE-2017-5925  Candidate  Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.  Assigned (20170207)  None (candidate not yet proposed)    View
102746  CVE-2017-5926  Candidate  Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.  Assigned (20170207)  None (candidate not yet proposed)    View
102747  CVE-2017-5927  Candidate  Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.  Assigned (20170207)  None (candidate not yet proposed)    View
102748  CVE-2017-5928  Candidate  The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now "Time to Tick" approach even with the https://bugzilla.mozilla.org/show_bug.cgi?id=1167489#c9 protection mechanism in place, which makes it easier for remote attackers to conduct AnC attacks via crafted JavaScript code.  Assigned (20170207)  None (candidate not yet proposed)    View

Page 1022 of 20943, showing 5 records out of 104715 total, starting on record 5106, ending on 5110

Actions