CVE List

Id CVE No. Status Description Phase Votes Comments Actions
103235  CVE-2017-6415  Candidate  The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DEX file.  Assigned (20170301)  None (candidate not yet proposed)    View
103234  CVE-2017-6414  Candidate  Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object.  Assigned (20170301)  None (candidate not yet proposed)    View
103233  CVE-2017-6413  Candidate  The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.  Assigned (20170301)  None (candidate not yet proposed)    View
103232  CVE-2017-6412  Candidate  In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.  Assigned (20170301)  None (candidate not yet proposed)    View
103231  CVE-2017-6411  Candidate  Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password.  Assigned (20170301)  None (candidate not yet proposed)    View

Page 297 of 20943, showing 5 records out of 104715 total, starting on record 1481, ending on 1485

Actions