CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102770  CVE-2017-5950  Candidate  The SingleDocParser::HandleNode function in yaml-cpp (aka LibYaml-C++) 0.5.3 allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted YAML file.  Assigned (20170209)  None (candidate not yet proposed)    View
102769  CVE-2017-5949  Candidate  JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript code that triggers access to red-zone memory locations, related to jit/ThunkGenerators.cpp, llint/LowLevelInterpreter32_64.asm, and llint/LowLevelInterpreter64.asm.  Assigned (20170209)  None (candidate not yet proposed)    View
102768  CVE-2017-5948  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170209)  None (candidate not yet proposed)    View
102767  CVE-2017-5947  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170209)  None (candidate not yet proposed)    View
102766  CVE-2017-5946  Candidate  The Zip::File component in the rubyzip gem before 1.2.1 for Ruby has a directory traversal vulnerability. If a site allows uploading of .zip files, an attacker can upload a malicious file that uses "../" pathname substrings to write arbitrary files to the filesystem.  Assigned (20170209)  None (candidate not yet proposed)    View

Page 390 of 20943, showing 5 records out of 104715 total, starting on record 1946, ending on 1950

Actions