CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104411  CVE-2017-7591  Candidate  OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/.  Assigned (20170408)  None (candidate not yet proposed)    View
104412  CVE-2017-7592  Candidate  The putagreytile function in tif_getimage.c in LibTIFF 4.0.7 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image.  Assigned (20170409)  None (candidate not yet proposed)    View
104413  CVE-2017-7593  Candidate  tif_read.c in LibTIFF 4.0.7 does not ensure that tif_rawdata is properly initialized, which might allow remote attackers to obtain sensitive information from process memory via a crafted image.  Assigned (20170409)  None (candidate not yet proposed)    View
104414  CVE-2017-7594  Candidate  The OJPEGReadHeaderInfoSecTablesDcTable function in tif_ojpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (memory leak) via a crafted image.  Assigned (20170409)  None (candidate not yet proposed)    View
104415  CVE-2017-7595  Candidate  The JPEGSetupEncode function in tiff_jpeg.c in LibTIFF 4.0.7 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted image.  Assigned (20170409)  None (candidate not yet proposed)    View

Page 20883 of 20943, showing 5 records out of 104715 total, starting on record 104411, ending on 104415

Actions