CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102750  CVE-2017-5930  Candidate  The AliasHandler component in PostfixAdmin before 3.0.2 allows remote authenticated domain admins to delete protected aliases via the delete parameter to delete.php, involving a missing permission check.  Assigned (20170207)  None (candidate not yet proposed)    View
102749  CVE-2017-5929  Candidate  QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components.  Assigned (20170207)  None (candidate not yet proposed)    View
102748  CVE-2017-5928  Candidate  The W3C High Resolution Time API, as implemented in various web browsers, does not consider that memory-reference times can be measured by a performance.now "Time to Tick" approach even with the https://bugzilla.mozilla.org/show_bug.cgi?id=1167489#c9 protection mechanism in place, which makes it easier for remote attackers to conduct AnC attacks via crafted JavaScript code.  Assigned (20170207)  None (candidate not yet proposed)    View
102747  CVE-2017-5927  Candidate  Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.  Assigned (20170207)  None (candidate not yet proposed)    View
102746  CVE-2017-5926  Candidate  Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.  Assigned (20170207)  None (candidate not yet proposed)    View

Page 394 of 20943, showing 5 records out of 104715 total, starting on record 1966, ending on 1970

Actions