CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102780  CVE-2017-5960  Candidate  An issue was discovered in Phalcon Eye through 0.4.1. The vulnerability exists due to insufficient filtration of user-supplied data in multiple HTTP GET parameters passed to the "phalconeye-master/public/external/pydio/plugins/editor.webodf/frame.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170211)  None (candidate not yet proposed)    View
102779  CVE-2017-5959  Candidate  CSRF token bypass in GeniXCMS before 1.0.2 could result in escalation of privileges. The forgotpassword.php page can be used to acquire a token.  Assigned (20170210)  None (candidate not yet proposed)    View
102778  CVE-2017-5958  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170210)  None (candidate not yet proposed)    View
102777  CVE-2017-5957  Candidate  Stack-based buffer overflow in the vrend_decode_set_framebuffer_state function in vrend_decode.c in virglrenderer before 926b9b3460a48f6454d8bbe9e44313d86a65447f, as used in Quick Emulator (QEMU), allows a local guest users to cause a denial of service (application crash) via the "nr_cbufs" argument.  Assigned (20170210)  None (candidate not yet proposed)    View
102776  CVE-2017-5956  Candidate  The vrend_draw_vbo function in virglrenderer before 0.6.0 allows local guest OS users to cause a denial of service (out-of-bounds array access and QEMU process crash) via vectors involving vertext_buffer_index.  Assigned (20170210)  None (candidate not yet proposed)    View

Page 388 of 20943, showing 5 records out of 104715 total, starting on record 1936, ending on 1940

Actions