CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102655  CVE-2017-5835  Candidate  libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero.  Assigned (20170201)  None (candidate not yet proposed)    View
102654  CVE-2017-5834  Candidate  The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file.  Assigned (20170201)  None (candidate not yet proposed)    View
102653  CVE-2017-5833  Candidate  Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.  Assigned (20170201)  None (candidate not yet proposed)    View
102652  CVE-2017-5832  Candidate  Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user"s email address.  Assigned (20170201)  None (candidate not yet proposed)    View
102651  CVE-2017-5831  Candidate  Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.  Assigned (20170201)  None (candidate not yet proposed)    View

Page 413 of 20943, showing 5 records out of 104715 total, starting on record 2061, ending on 2065

Actions