CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102750  CVE-2017-5930  Candidate  The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.  Assigned (20170207)  None (candidate not yet proposed)    View
102751  CVE-2017-5931  Candidate  Integer overflow in hw/virtio/virtio-crypto.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (QEMU process crash) or possibly execute arbitrary code on the host via a crafted virtio-crypto request, which triggers a heap-based buffer overflow.  Assigned (20170207)  None (candidate not yet proposed)    View
102752  CVE-2017-5932  Candidate  The path autocompletion feature in Bash 4.4 allows local users to gain privileges via a crafted filename starting with a " (double quote) character and a command substitution metacharacter.  Assigned (20170207)  None (candidate not yet proposed)    View
87720  CVE-2016-10209  Candidate  The archive_wstring_append_from_mbs function in archive_string.c in libarchive 3.2.2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted archive file.  Assigned (20170207)  None (candidate not yet proposed)    View
87722  CVE-2016-10210  Candidate  libyara/lexer.l in YARA 3.5.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted rule that is mishandled in the yy_get_next_buffer function.  Assigned (20170207)  None (candidate not yet proposed)    View

Page 19928 of 20943, showing 5 records out of 104715 total, starting on record 99636, ending on 99640

Actions