CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87631  CVE-2016-10128  Candidate  Buffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted non-flush packet.  Assigned (20170110)  None (candidate not yet proposed)    View
87632  CVE-2016-10129  Candidate  The Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.  Assigned (20170110)  None (candidate not yet proposed)    View
87634  CVE-2016-10130  Candidate  The http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.  Assigned (20170110)  None (candidate not yet proposed)    View
102160  CVE-2017-5340  Candidate  Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.  Assigned (20170111)  None (candidate not yet proposed)    View
102161  CVE-2017-5341  Candidate  The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print().  Assigned (20170111)  None (candidate not yet proposed)    View

Page 19793 of 20943, showing 5 records out of 104715 total, starting on record 98961, ending on 98965

Actions