CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102655 | CVE-2017-5835 | Candidate | libplist allows attackers to cause a denial of service (large memory allocation and crash) via vectors involving an offset size of zero. | Assigned (20170201) | None (candidate not yet proposed) | View | |
102654 | CVE-2017-5834 | Candidate | The parse_dict_node function in bplist.c in libplist allows attackers to cause a denial of service (out-of-bounds heap read and crash) via a crafted file. | Assigned (20170201) | None (candidate not yet proposed) | View | |
102653 | CVE-2017-5833 | Candidate | Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | Assigned (20170201) | None (candidate not yet proposed) | View | |
102652 | CVE-2017-5832 | Candidate | Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user"s email address. | Assigned (20170201) | None (candidate not yet proposed) | View | |
102651 | CVE-2017-5831 | Candidate | Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID. | Assigned (20170201) | None (candidate not yet proposed) | View |
Page 413 of 20943, showing 5 records out of 104715 total, starting on record 2061, ending on 2065