CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102799  CVE-2017-5979  Candidate  The prescan_entry function in fseeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file.  Assigned (20170213)  None (candidate not yet proposed)    View
102800  CVE-2017-5980  Candidate  The zzip_mem_entry_new function in memdisk.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted ZIP file.  Assigned (20170213)  None (candidate not yet proposed)    View
102801  CVE-2017-5981  Candidate  seeko.c in zziplib 0.13.62 allows remote attackers to cause a denial of service (assertion failure and crash) via a crafted ZIP file.  Assigned (20170213)  None (candidate not yet proposed)    View
102802  CVE-2017-5982  Candidate  Directory traversal vulnerability in the Chorus2 2.4.2 add-on for Kodi allows remote attackers to read arbitrary files via a %2E%2E%252e (encoded dot dot slash) in the image path, as demonstrated by image/image%3A%2F%2F%2e%2e%252fetc%252fpasswd.  Assigned (20170213)  None (candidate not yet proposed)    View
102803  CVE-2017-5983  Candidate  The JIRA Workflow Designer Plugin in Atlassian JIRA Server before 6.3.0 improperly uses an XML parser and deserializer, which allows remote attackers to execute arbitrary code, read arbitrary files, or cause a denial of service via a crafted serialized Java object.  Assigned (20170213)  None (candidate not yet proposed)    View

Page 19941 of 20943, showing 5 records out of 104715 total, starting on record 99701, ending on 99705

Actions