CVE List

Id CVE No. Status Description Phase Votes Comments Actions
103775  CVE-2017-6955  Candidate  An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack.  Assigned (20170317)  None (candidate not yet proposed)    View
103774  CVE-2017-6954  Candidate  An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions.  Assigned (20170317)  None (candidate not yet proposed)    View
103773  CVE-2017-6953  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170316)  None (candidate not yet proposed)    View
103772  CVE-2017-6952  Candidate  Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or possibly have unspecified other impact via a large value.  Assigned (20170316)  None (candidate not yet proposed)    View
103771  CVE-2017-6951  Candidate  The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type.  Assigned (20170316)  None (candidate not yet proposed)    View

Page 189 of 20943, showing 5 records out of 104715 total, starting on record 941, ending on 945

Actions