CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104420  CVE-2017-7600  Candidate  LibTIFF 4.0.7 has an "outside the range of representable values of type unsigned char" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.  Assigned (20170409)  None (candidate not yet proposed)    View
39140  CVE-2009-1705  Candidate  CoreGraphics in Apple Safari before 4.0 on Windows does not properly use arithmetic during automatic hinting of TrueType fonts, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted font data.  Assigned (20090520)  None (candidate not yet proposed)    View
104676  CVE-2017-7856  Candidate  LibreOffice before 2017-03-11 has an out-of-bounds write caused by a heap-based buffer overflow in the SVMConverter::ImplConvertFromSVM1 function in vcl/source/gdi/svmconverter.cxx.  Assigned (20170414)  None (candidate not yet proposed)    View
39396  CVE-2009-1961  Candidate  The inode double locking code in fs/ocfs2/file.c in the Linux kernel 2.6.30 before 2.6.30-rc3, 2.6.27 before 2.6.27.24, 2.6.29 before 2.6.29.4, and possibly other versions down to 2.6.19 allows local users to cause a denial of service (prevention of file creation and removal) via a series of splice system calls that trigger a deadlock between the generic_file_splice_write, splice_from_pipe, and ocfs2_file_splice_write functions.  Assigned (20090606)  None (candidate not yet proposed)    View
39652  CVE-2009-2217  Candidate  Cross-site scripting (XSS) vulnerability in NBBC before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via an invalid URL in a BBCode img tag.  Assigned (20090625)  None (candidate not yet proposed)    View

Page 18804 of 20943, showing 5 records out of 104715 total, starting on record 94016, ending on 94020

Actions