CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102465  CVE-2017-5645  Candidate  In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.  Assigned (20170129)  None (candidate not yet proposed)    View
102464  CVE-2017-5644  Candidate  Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack.  Assigned (20170129)  None (candidate not yet proposed)    View
102463  CVE-2017-5643  Candidate  Apache Camel"s Validation Component is vulnerable against SSRF via remote DTDs and XXE.  Assigned (20170129)  None (candidate not yet proposed)    View
102462  CVE-2017-5642  Candidate  During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs.  Assigned (20170129)  None (candidate not yet proposed)    View
102461  CVE-2017-5641  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170129)  None (candidate not yet proposed)    View

Page 451 of 20943, showing 5 records out of 104715 total, starting on record 2251, ending on 2255

Actions