CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102490  CVE-2017-5670  Candidate  Riverbed RiOS through 9.6.0 deletes the secure vault with the rm program (not shred or srm), which makes it easier for physically proximate attackers to obtain sensitive information by reading raw disk blocks.  Assigned (20170131)  None (candidate not yet proposed)    View
102489  CVE-2017-5669  Candidate  The do_shmat function in ipc/shm.c in the Linux kernel through 4.9.12 does not restrict the address calculated by a certain rounding operation, which allows local users to map page zero, and consequently bypass a protection mechanism that exists for the mmap system call, by making crafted shmget and shmat system calls in a privileged context.  Assigned (20170131)  None (candidate not yet proposed)    View
102488  CVE-2017-5668  Candidate  bitlbee-libpurple before 3.5.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) and possibly execute arbitrary code via a file transfer request for a contact that is not in the contact list. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-10189.  Assigned (20170131)  None (candidate not yet proposed)    View
102487  CVE-2017-5667  Candidate  The sdhci_sdma_transfer_multi_blocks function in hw/sd/sdhci.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (out-of-bounds heap access and crash) or execute arbitrary code on the QEMU host via vectors involving the data transfer length.  Assigned (20170131)  None (candidate not yet proposed)    View
102486  CVE-2017-5666  Candidate  The free_options function in options_manager.c in mp3splt 2.6.2 allows remote attackers to cause a denial of service (invalid free and crash) via a crafted file.  Assigned (20170131)  None (candidate not yet proposed)    View

Page 446 of 20943, showing 5 records out of 104715 total, starting on record 2226, ending on 2230

Actions