CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104120  CVE-2017-7300  Candidate  The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an aout_link_add_symbols function in bfd/aoutx.h that is vulnerable to a heap-based buffer over-read (off-by-one) because of an incomplete check for invalid string offsets while loading symbols, leading to a GNU linker (ld) program crash.  Assigned (20170329)  None (candidate not yet proposed)    View
104119  CVE-2017-7299  Candidate  The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before trying to read the ELF reloc section header. The vulnerability leads to a GNU linker (ld) program crash.  Assigned (20170329)  None (candidate not yet proposed)    View
104118  CVE-2017-7298  Candidate  In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.  Assigned (20170329)  None (candidate not yet proposed)    View
104117  CVE-2017-7297  Candidate  Rancher Labs rancher server 1.2.0+ is vulnerable to authenticated users disabling access control via an API call. This is fixed in versions rancher/server:v1.2.4, rancher/server:v1.3.5, rancher/server:v1.4.3, and rancher/server:v1.5.3.  Assigned (20170328)  None (candidate not yet proposed)    View
104116  CVE-2017-7296  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170328)  None (candidate not yet proposed)    View

Page 120 of 20943, showing 5 records out of 104715 total, starting on record 596, ending on 600

Actions