CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
103235 | CVE-2017-6415 | Candidate | The dex_parse_debug_item function in libr/bin/p/bin_dex.c in radare2 1.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted DEX file. | Assigned (20170301) | None (candidate not yet proposed) | View | |
103234 | CVE-2017-6414 | Candidate | Memory leak in the vcard_apdu_new function in card_7816.c in libcacard before 2.5.3 allows local guest OS users to cause a denial of service (host memory consumption) via vectors related to allocating a new APDU object. | Assigned (20170301) | None (candidate not yet proposed) | View | |
103233 | CVE-2017-6413 | Candidate | The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.6 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "AuthType oauth20" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic. | Assigned (20170301) | None (candidate not yet proposed) | View | |
103232 | CVE-2017-6412 | Candidate | In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310. | Assigned (20170301) | None (candidate not yet proposed) | View | |
103231 | CVE-2017-6411 | Candidate | Cross Site Request Forgery (CSRF) on D-Link DSL-2730U C1 IN_1.00 devices allows remote attackers to change the DNS or firewall configuration or any password. | Assigned (20170301) | None (candidate not yet proposed) | View |
Page 297 of 20943, showing 5 records out of 104715 total, starting on record 1481, ending on 1485