CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102652  CVE-2017-5832  Candidate  Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user"s email address.  Assigned (20170201)  None (candidate not yet proposed)    View
102653  CVE-2017-5833  Candidate  Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.  Assigned (20170201)  None (candidate not yet proposed)    View
102654  CVE-2017-5834  Candidate  The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.  Assigned (20170201)  None (candidate not yet proposed)    View
102655  CVE-2017-5835  Candidate  libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.  Assigned (20170201)  None (candidate not yet proposed)    View
102678  CVE-2017-5858  Candidate  An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for Converse.js (0.8.0 - 1.0.6, 2.0.0 - 2.0.4).  Assigned (20170202)  None (candidate not yet proposed)    View

Page 19911 of 20943, showing 5 records out of 104715 total, starting on record 99551, ending on 99555

Actions