CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102704 | CVE-2017-5884 | Candidate | gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile. | Assigned (20170204) | None (candidate not yet proposed) | View | |
102705 | CVE-2017-5885 | Candidate | Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow. | Assigned (20170204) | None (candidate not yet proposed) | View | |
102706 | CVE-2017-5886 | Candidate | Heap-based buffer overflow in the PoDoFo::PdfTokenizer::GetNextToken function in PdfTokenizer.cpp in PoDoFo 0.9.4 allows remote attackers to have unspecified impact via a crafted file. | Assigned (20170204) | None (candidate not yet proposed) | View | |
87711 | CVE-2016-10200 | Candidate | Race condition in the L2TPv3 IP Encapsulation feature in the Linux kernel before 4.8.14 allows local users to gain privileges or cause a denial of service (use-after-free) by making multiple bind system calls without properly ascertaining whether a socket has the SOCK_ZAPPED status, related to net/l2tp/l2tp_ip.c and net/l2tp/l2tp_ip6.c. | Assigned (20170204) | None (candidate not yet proposed) | View | |
87712 | CVE-2016-10201 | Candidate | Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the format parameter in a download log request to index.php. | Assigned (20170204) | None (candidate not yet proposed) | View |
Page 1026 of 20943, showing 5 records out of 104715 total, starting on record 5126, ending on 5130