CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102675  CVE-2017-5855  Candidate  The PoDoFo::PdfParser::ReadXRefSubsection function in PdfParser.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file.  Assigned (20170201)  None (candidate not yet proposed)    View
102676  CVE-2017-5856  Candidate  Memory leak in the megasas_handle_dcmd function in hw/scsi/megasas.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption) via MegaRAID Firmware Interface (MFI) commands with the sglist size set to a value over 2 Gb.  Assigned (20170201)  None (candidate not yet proposed)    View
102677  CVE-2017-5857  Candidate  Memory leak in the virgl_cmd_resource_unref function in hw/display/virtio-gpu-3d.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_UNREF commands sent without detaching the backing storage beforehand.  Assigned (20170201)  None (candidate not yet proposed)    View
102496  CVE-2017-5676  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170201)  None (candidate not yet proposed)    View
102497  CVE-2017-5677  Candidate  PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression.  Assigned (20170201)  None (candidate not yet proposed)    View

Page 1037 of 20943, showing 5 records out of 104715 total, starting on record 5181, ending on 5185

Actions