CVE List

Id CVE No. Status Description Phase Votes Comments Actions
103323  CVE-2017-6503  Candidate  WebUI in qBittorrent before 3.3.11 did not escape many values, which could potentially lead to XSS.  Assigned (20170305)  None (candidate not yet proposed)    View
103324  CVE-2017-6504  Candidate  WebUI in qBittorrent before 3.3.11 did not set the X-Frame-Options header, which could potentially lead to clickjacking.  Assigned (20170305)  None (candidate not yet proposed)    View
87758  CVE-2016-10243  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170305)  None (candidate not yet proposed)    View
103325  CVE-2017-6505  Candidate  The ohci_service_ed_list function in hw/usb/hcd-ohci.c in QEMU (aka Quick Emulator) allows local guest OS users to cause a denial of service (infinite loop) via vectors involving the number of link endpoint list descriptors.  Assigned (20170306)  None (candidate not yet proposed)    View
103326  CVE-2017-6506  Candidate  In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.  Assigned (20170306)  None (candidate not yet proposed)    View

Page 20059 of 20943, showing 5 records out of 104715 total, starting on record 100291, ending on 100295

Actions