CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87718  CVE-2016-10207  Candidate  The Xvnc server in TigerVNC allows remote attackers to cause a denial of service (invalid memory access and crash) by terminating a TLS handshake early.  Assigned (20170204)  None (candidate not yet proposed)    View
87719  CVE-2016-10208  Candidate  The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block groups, which allows physically proximate attackers to cause a denial of service (out-of-bounds read and system crash) via a crafted ext4 image.  Assigned (20170204)  None (candidate not yet proposed)    View
102698  CVE-2017-5878  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170203)  None (candidate not yet proposed)    View
102699  CVE-2017-5879  Candidate  An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects source_selector.php and the following parameter: src.  Assigned (20170203)  None (candidate not yet proposed)    View
102700  CVE-2017-5880  Candidate  Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x before 6.0.13, 5.0.x before 5.0.17 and Splunk Light versions before 6.5.2 allows remote authenticated users to cause a denial of service (daemon crash) via a crafted GET request, aka SPL-130279.  Assigned (20170203)  None (candidate not yet proposed)    View

Page 1028 of 20943, showing 5 records out of 104715 total, starting on record 5136, ending on 5140

Actions