CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104705  CVE-2017-7885  Candidate  Artifex jbig2dec 0.13 has a heap-based buffer over-read leading to denial of service (application crash) or disclosure of sensitive information from process memory, because of an integer overflow in the jbig2_decode_symbol_dict function in jbig2_symbol_dict.c in libjbig2dec.a during operation on a crafted .jb2 file.  Assigned (20170416)  None (candidate not yet proposed)    View
104704  CVE-2017-7884  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170416)  None (candidate not yet proposed)    View
104703  CVE-2017-7883  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170415)  None (candidate not yet proposed)    View
104702  CVE-2017-7882  Candidate  LibreOffice before 2017-03-14 has an out-of-bounds write related to the HWPFile::TagsRead function in hwpfilter/source/hwpfile.cxx.  Assigned (20170415)  None (candidate not yet proposed)    View
104701  CVE-2017-7881  Candidate  BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.  Assigned (20170415)  None (candidate not yet proposed)    View

Page 3 of 20943, showing 5 records out of 104715 total, starting on record 11, ending on 15

<<first 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 last>>

Actions