CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102705  CVE-2017-5885  Candidate  Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code via vectors involving SetColorMapEntries, which triggers a buffer overflow.  Assigned (20170204)  None (candidate not yet proposed)    View
102704  CVE-2017-5884  Candidate  gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.  Assigned (20170204)  None (candidate not yet proposed)    View
102703  CVE-2017-5883  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170204)  None (candidate not yet proposed)    View
102702  CVE-2017-5882  Candidate  Cross-site scripting (XSS) vulnerability in index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter.  Assigned (20170204)  None (candidate not yet proposed)    View
102701  CVE-2017-5881  Candidate  GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file.  Assigned (20170203)  None (candidate not yet proposed)    View

Page 403 of 20943, showing 5 records out of 104715 total, starting on record 2011, ending on 2015

Actions