CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102759  CVE-2017-5939  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170209)  None (candidate not yet proposed)    View
102760  CVE-2017-5940  Candidate  Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-5180.  Assigned (20170209)  None (candidate not yet proposed)    View
102761  CVE-2017-5941  Candidate  An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).  Assigned (20170209)  None (candidate not yet proposed)    View
102762  CVE-2017-5942  Candidate  An issue was discovered in the WP Mail plugin before 1.2 for WordPress. The replyto parameter when composing a mail allows for a reflected XSS. This would allow you to execute JavaScript in the context of the user receiving the mail.  Assigned (20170209)  None (candidate not yet proposed)    View
102763  CVE-2017-5943  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170209)  None (candidate not yet proposed)    View

Page 19931 of 20943, showing 5 records out of 104715 total, starting on record 99651, ending on 99655

Actions