CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102757  CVE-2017-5937  Candidate  The util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d project (aka virglrenderer) 0.6.0 and earlier allows local guest OS users to cause a denial of service (NULL pointer dereference) via a crafted VIRGL_CCMD_CLEAR command.  Assigned (20170208)  None (candidate not yet proposed)    View
102758  CVE-2017-5938  Candidate  Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name.  Assigned (20170208)  None (candidate not yet proposed)    View
87724  CVE-2016-10212  Candidate  Radware devices use the same value for the first two GCM nonces, which allows remote attackers to obtain the authentication key and spoof data via a "forbidden attack," a similar issue to CVE-2016-0270. NOTE: this issue may be due to the use of a third-party Cavium product.  Assigned (20170208)  None (candidate not yet proposed)    View
87725  CVE-2016-10213  Candidate  A10 AX1030 and possibly other devices with software before 2.7.2-P8 uses random GCM nonce generations, which makes it easier for remote attackers to obtain the authentication key and spoof data by leveraging a reused nonce in a session and a "forbidden attack," a similar issue to CVE-2016-0270.  Assigned (20170208)  None (candidate not yet proposed)    View
87726  CVE-2016-10214  Candidate  Memory leak in the virgl_resource_attach_backing function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (memory consumption) via a large number of VIRTIO_GPU_CMD_RESOURCE_ATTACH_BACKING commands.  Assigned (20170208)  None (candidate not yet proposed)    View

Page 19930 of 20943, showing 5 records out of 104715 total, starting on record 99646, ending on 99650

Actions