CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104065  CVE-2017-7245  Candidate  Stack-based buffer overflow in the pcre32_copy_substring function in pcre_get.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (WRITE of size 4) or possibly have unspecified other impact via a crafted file.  Assigned (20170323)  None (candidate not yet proposed)    View
104064  CVE-2017-7244  Candidate  The _pcre32_xclass function in pcre_xclass.c in libpcre1 in PCRE 8.40 allows remote attackers to cause a denial of service (invalid memory read) via a crafted file.  Assigned (20170323)  None (candidate not yet proposed)    View
104063  CVE-2017-7243  Candidate  Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake.  Assigned (20170323)  None (candidate not yet proposed)    View
104062  CVE-2017-7242  Candidate  Multiple Cross-Site Scripting (XSS) were discovered in admin/modules components in SLiMS 7 Cendana through 2017-03-23: the keywords parameter to bibliography/checkout_item.php, bibliography/dl_print.php, bibliography/item.php, bibliography/item_barcode_generator.php, bibliography/printed_card.php, circulation/loan_rules.php, master_file/author.php, master_file/coll_type.php, and master_file/doc_language.php and the quickReturnID field to circulation/ajax_action.php.  Assigned (20170323)  None (candidate not yet proposed)    View
104061  CVE-2017-7241  Candidate  A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted "type" parameter, if Content Security Protection (CSP) settings allows it. This is fixed in 1.3.9, 2.1.3, and 2.2.3. Note that this vulnerability is not exploitable if the admin tools directory is removed, as recommended in the "Post-installation and upgrade tasks" of the MantisBT Admin Guide. A reminder to do so is also displayed on the login page.  Assigned (20170323)  None (candidate not yet proposed)    View

Page 131 of 20943, showing 5 records out of 104715 total, starting on record 651, ending on 655

Actions