CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102704  CVE-2017-5884  Candidate  gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.  Assigned (20170204)  None (candidate not yet proposed)    View
102705  CVE-2017-5885  Candidate  Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.  Assigned (20170204)  None (candidate not yet proposed)    View
102706  CVE-2017-5886  Candidate  Heap-based buffer overflow in the PoDoFo::PdfTokenizer::GetNextToken function in PdfTokenizer.cpp in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file.  Assigned (20170204)  None (candidate not yet proposed)    View
87711  CVE-2016-10200  Candidate  Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c.  Assigned (20170204)  None (candidate not yet proposed)    View
87712  CVE-2016-10201  Candidate  Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter in a download log request to index.php.  Assigned (20170204)  None (candidate not yet proposed)    View

Page 1026 of 20943, showing 5 records out of 104715 total, starting on record 5126, ending on 5130

Actions