CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102396  CVE-2017-5576  Candidate  Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted size value in a VC4_SUBMIT_CL ioctl call.  Assigned (20170124)  None (candidate not yet proposed)    View
102397  CVE-2017-5577  Candidate  The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 does not set an errno value upon certain overflow detections, which allows local users to cause a denial of service (incorrect pointer dereference and OOPS) via inconsistent size values in a VC4_SUBMIT_CL ioctl call.  Assigned (20170124)  None (candidate not yet proposed)    View
102389  CVE-2017-5569  Candidate  An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the template.jsp, which can be exploited without the need of authentication and via an HTTP POST request, and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().  Assigned (20170123)  None (candidate not yet proposed)    View
102390  CVE-2017-5570  Candidate  An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJson.jsp, which can only be exploited by authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().  Assigned (20170123)  None (candidate not yet proposed)    View
102391  CVE-2017-5571  Candidate  Open redirect vulnerability in the lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) 11.14.1 and earlier, as used in Citrix License Server for Windows and the Citrix License Server VPX, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.  Assigned (20170123)  None (candidate not yet proposed)    View

Page 1098 of 20943, showing 5 records out of 104715 total, starting on record 5486, ending on 5490

Actions