CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
103775 | CVE-2017-6955 | Candidate | An issue was discovered in by-email/by-email.php in the Invite Anyone plugin before 1.3.15 for WordPress. A user is able to change the subject and the body of the invitation mail that should be immutable, which facilitates a social engineering attack. | Assigned (20170317) | None (candidate not yet proposed) | View | |
103774 | CVE-2017-6954 | Candidate | An issue was discovered in includes/component.php in the BuddyPress Docs plugin before 1.9.3 for WordPress. It is possible for authenticated users to edit documents of other users without proper permissions. | Assigned (20170317) | None (candidate not yet proposed) | View | |
103773 | CVE-2017-6953 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170316) | None (candidate not yet proposed) | View | |
103772 | CVE-2017-6952 | Candidate | Integer overflow in the cs_winkernel_malloc function in winkernel_mm.c in Capstone 3.0.4 and earlier allows attackers to cause a denial of service (heap-based buffer overflow in a kernel driver) or possibly have unspecified other impact via a large value. | Assigned (20170316) | None (candidate not yet proposed) | View | |
103771 | CVE-2017-6951 | Candidate | The keyring_search_aux function in security/keys/keyring.c in the Linux kernel through 3.14.79 allows local users to cause a denial of service (NULL pointer dereference and OOPS) via a request_key system call for the "dead" type. | Assigned (20170316) | None (candidate not yet proposed) | View |
Page 189 of 20943, showing 5 records out of 104715 total, starting on record 941, ending on 945