CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102760 | CVE-2017-5940 | Candidate | Firejail before 0.9.44.6 and 0.9.38.x LTS before 0.9.38.10 LTS does not comprehensively address dotfile cases during its attempt to prevent accessing user files with an euid of zero, which allows local users to conduct sandbox-escape attacks via vectors involving a symlink and the --private option. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-5180. | Assigned (20170209) | None (candidate not yet proposed) | View | |
102759 | CVE-2017-5939 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170209) | None (candidate not yet proposed) | View | |
102758 | CVE-2017-5938 | Candidate | Cross-site scripting (XSS) vulnerability in the nav_path function in lib/viewvc.py in ViewVC before 1.1.26 allows remote attackers to inject arbitrary web script or HTML via the nav_data name. | Assigned (20170208) | None (candidate not yet proposed) | View | |
102757 | CVE-2017-5937 | Candidate | The util_format_is_pure_uint function in vrend_renderer.c in Virgil 3d project (aka virglrenderer) 0.6.0 and earlier allows local guest OS users to cause a denial of service (NULL pointer dereference) via a crafted VIRGL_CCMD_CLEAR command. | Assigned (20170208) | None (candidate not yet proposed) | View | |
102756 | CVE-2017-5936 | Candidate | OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions. | Assigned (20170208) | None (candidate not yet proposed) | View |
Page 392 of 20943, showing 5 records out of 104715 total, starting on record 1956, ending on 1960