CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102799 | CVE-2017-5979 | Candidate | The prescan_entry function in fseeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file. | Assigned (20170213) | None (candidate not yet proposed) | View | |
102800 | CVE-2017-5980 | Candidate | The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file. | Assigned (20170213) | None (candidate not yet proposed) | View | |
102801 | CVE-2017-5981 | Candidate | seeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (assertion failure and crash) via a crafted ZIP file. | Assigned (20170213) | None (candidate not yet proposed) | View | |
102802 | CVE-2017-5982 | Candidate | Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd. | Assigned (20170213) | None (candidate not yet proposed) | View | |
102803 | CVE-2017-5983 | Candidate | The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object. | Assigned (20170213) | None (candidate not yet proposed) | View |
Page 19941 of 20943, showing 5 records out of 104715 total, starting on record 99701, ending on 99705