CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102652 | CVE-2017-5832 | Candidate | Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user"s email address. | Assigned (20170201) | None (candidate not yet proposed) | View | |
102653 | CVE-2017-5833 | Candidate | Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | Assigned (20170201) | None (candidate not yet proposed) | View | |
102654 | CVE-2017-5834 | Candidate | The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file. | Assigned (20170201) | None (candidate not yet proposed) | View | |
102655 | CVE-2017-5835 | Candidate | libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero. | Assigned (20170201) | None (candidate not yet proposed) | View | |
102678 | CVE-2017-5858 | Candidate | An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for Converse.js (0.8.0 - 1.0.6, 2.0.0 - 2.0.4). | Assigned (20170202) | None (candidate not yet proposed) | View |
Page 19911 of 20943, showing 5 records out of 104715 total, starting on record 99551, ending on 99555