CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87672  CVE-2016-10165  Candidate  The Type_MLU_Read function in cmstypes.c in Little CMS (aka lcms2) allows remote attackers to obtain sensitive information or cause a denial of service via an image with a crafted ICC profile, which triggers an out-of-bounds heap read.  Assigned (20170125)  None (candidate not yet proposed)    View
102398  CVE-2017-5578  Candidate  Memory leak in the virtio_gpu_resource_attach_backing function in hw/display/virtio-gpu.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.  Assigned (20170125)  None (candidate not yet proposed)    View
102399  CVE-2017-5579  Candidate  Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.  Assigned (20170125)  None (candidate not yet proposed)    View
102418  CVE-2017-5598  Candidate  An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects the EmployeePortalServlet page and the following parameter: employer.  Assigned (20170127)  None (candidate not yet proposed)    View
102419  CVE-2017-5599  Candidate  An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a reflected Cross Site Scripting vulnerability which affects the raceMasterList.jsp page within the Patient Portal. Inserted payload is rendered within the Patient Portal and the raceMasterList.jsp page does not require authentication. The vulnerability can be used to extract sensitive information or perform attacks against the user"s browser. The vulnerability affects the raceMasterList.jsp page and the following parameter: race.  Assigned (20170127)  None (candidate not yet proposed)    View

Page 19852 of 20943, showing 5 records out of 104715 total, starting on record 99256, ending on 99260

Actions