CVE List

Id CVE No. Status Description Phase Votes Comments Actions
103170  CVE-2017-6350  Candidate  An integer overflow at an unserialize_uep memory allocation site would occur for vim before patch 8.0.0378, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.  Assigned (20170226)  None (candidate not yet proposed)    View
103169  CVE-2017-6349  Candidate  An integer overflow at a u_read_undo memory allocation site would occur for vim before patch 8.0.0377, if it does not properly validate values for tree length when reading a corrupted undo file, which may lead to resultant buffer overflows.  Assigned (20170226)  None (candidate not yet proposed)    View
103168  CVE-2017-6348  Candidate  The hashbin_delete function in net/irda/irqueue.c in the Linux kernel before 4.9.13 improperly manages lock dropping, which allows local users to cause a denial of service (deadlock) via crafted operations on IrDA devices.  Assigned (20170226)  None (candidate not yet proposed)    View
103167  CVE-2017-6347  Candidate  The ip_cmsg_recv_checksum function in net/ipv4/ip_sockglue.c in the Linux kernel before 4.10.1 has incorrect expectations about skb data layout, which allows local users to cause a denial of service (buffer over-read) or possibly have unspecified other impact via crafted system calls, as demonstrated by use of the MSG_MORE flag in conjunction with loopback UDP transmission.  Assigned (20170226)  None (candidate not yet proposed)    View
103166  CVE-2017-6346  Candidate  Race condition in net/packet/af_packet.c in the Linux kernel before 4.9.13 allows local users to cause a denial of service (use-after-free) or possibly have unspecified other impact via a multithreaded application that makes PACKET_FANOUT setsockopt system calls.  Assigned (20170226)  None (candidate not yet proposed)    View

Page 310 of 20943, showing 5 records out of 104715 total, starting on record 1546, ending on 1550

Actions