CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102810  CVE-2017-5990  Candidate  An issue was discovered in PhreeBooksERP before 2017-02-13. The vulnerability exists due to insufficient filtration of user-supplied data in the "form" HTTP GET parameter passed to the "PhreeBooksERP-master/extensions/ShippingMethods/ups/label_mgr/js_include.php" and "PhreeBooksERP-master/extensions/ShippingMethods/yrc/label_mgr/js_include.php" URLs. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. NOTE: these js_include.php files do not exist in the SourceForge "stable release" (aka R37RC1).  Assigned (20170215)  None (candidate not yet proposed)    View
102811  CVE-2017-5991  Candidate  An issue was discovered in Artifex Software, Inc. MuPDF before 1912de5f08e90af1d9d0a9791f58ba3afdb9d465. The pdf_run_xobject function in pdf-op-run.c encounters a NULL pointer dereference during a Fitz fz_paint_pixmap_with_mask painting operation.  Assigned (20170215)  None (candidate not yet proposed)    View
102812  CVE-2017-5992  Candidate  Openpyxl 2.4.1 resolves external entities by default, which allows remote attackers to conduct XXE attacks via a crafted .xlsx document.  Assigned (20170215)  None (candidate not yet proposed)    View
102813  CVE-2017-5993  Candidate  Memory leak in the vrend_renderer_init_blit_ctx function in vrend_blitter.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (host memory consumption) via a large number of VIRGL_CCMD_BLIT commands.  Assigned (20170215)  None (candidate not yet proposed)    View
102814  CVE-2017-5994  Candidate  Heap-based buffer overflow in the vrend_create_vertex_elements_state function in vrend_renderer.c in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and crash) via the num_elements parameter.  Assigned (20170215)  None (candidate not yet proposed)    View

Page 19944 of 20943, showing 5 records out of 104715 total, starting on record 99716, ending on 99720

Actions