CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102465 | CVE-2017-5645 | Candidate | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102464 | CVE-2017-5644 | Candidate | Apache POI in versions prior to release 3.15 allows remote attackers to cause a denial of service (CPU consumption) via a specially crafted OOXML file, aka an XML Entity Expansion (XEE) attack. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102463 | CVE-2017-5643 | Candidate | Apache Camel"s Validation Component is vulnerable against SSRF via remote DTDs and XXE. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102462 | CVE-2017-5642 | Candidate | During installation of Ambari 2.4.0 through 2.4.2, Ambari Server artifacts are not created with proper ACLs. | Assigned (20170129) | None (candidate not yet proposed) | View | |
102461 | CVE-2017-5641 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170129) | None (candidate not yet proposed) | View |
Page 451 of 20943, showing 5 records out of 104715 total, starting on record 2251, ending on 2255