CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87722  CVE-2016-10210  Candidate  libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rule that is mishandled in the yy_get_next_buffer function.  Assigned (20170207)  None (candidate not yet proposed)    View
87723  CVE-2016-10211  Candidate  libyara/grammar.y in YARA 3.5.0 allows remote attackers to cause a denial of service (use-after-free and application crash) via a crafted rule that is mishandled in the yr_parser_lookup_loop_variable function.  Assigned (20170207)  None (candidate not yet proposed)    View
102707  CVE-2017-5887  Candidate  WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function).  Assigned (20170206)  None (candidate not yet proposed)    View
102708  CVE-2017-5888  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170206)  None (candidate not yet proposed)    View
102709  CVE-2017-5889  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170206)  None (candidate not yet proposed)    View

Page 1024 of 20943, showing 5 records out of 104715 total, starting on record 5116, ending on 5120

Actions