CVE List

Id CVE No. Status Description Phase Votes Comments Actions
103230  CVE-2017-6410  Candidate  kpac/script.cpp in KDE kio before 5.32 and kdelibs before 4.14.30 calls the PAC FindProxyForURL function with a full https URL (potentially including Basic Authentication credentials, a query string, or PATH_INFO), which allows remote attackers to obtain sensitive information via a crafted PAC file.  Assigned (20170301)  None (candidate not yet proposed)    View
103231  CVE-2017-6411  Candidate  Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.  Assigned (20170301)  None (candidate not yet proposed)    View
103232  CVE-2017-6412  Candidate  In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.  Assigned (20170301)  None (candidate not yet proposed)    View
103233  CVE-2017-6413  Candidate  The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.  Assigned (20170301)  None (candidate not yet proposed)    View
103234  CVE-2017-6414  Candidate  Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.  Assigned (20170301)  None (candidate not yet proposed)    View

Page 20034 of 20943, showing 5 records out of 104715 total, starting on record 100166, ending on 100170

Actions