CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104095  CVE-2017-7275  Candidate  The ReadPCXImage function in coders/pcx.c in ImageMagick 7.0.4.9 allows remote attackers to cause a denial of service (attempted large memory allocation and application crash) via a crafted file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8862 and CVE-2016-8866.  Assigned (20170327)  None (candidate not yet proposed)    View
104094  CVE-2017-7274  Candidate  The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PE file.  Assigned (20170327)  None (candidate not yet proposed)    View
104093  CVE-2017-7273  Candidate  The cp_report_fixup function in drivers/hid/hid-cypress.c in the Linux kernel 4.x before 4.9.4 allows physically proximate attackers to cause a denial of service (integer underflow) or possibly have unspecified other impact via a crafted HID report.  Assigned (20170327)  None (candidate not yet proposed)    View
104092  CVE-2017-7272  Candidate  PHP through 7.1.3 enables potential SSRF in applications that accept an fsockopen hostname argument with an expectation that the port number is constrained. Because a :port syntax is recognized, fsockopen will use the port number that is specified in the hostname argument, instead of the port number in the second argument of the function.  Assigned (20170327)  None (candidate not yet proposed)    View
104091  CVE-2017-7271  Candidate  Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen.  Assigned (20170327)  None (candidate not yet proposed)    View

Page 125 of 20943, showing 5 records out of 104715 total, starting on record 621, ending on 625

Actions