CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102160  CVE-2017-5340  Candidate  Zend/zend_hash.c in PHP before 7.0.15 and 7.1.x before 7.1.1 mishandles certain cases that require large array allocations, which allows remote attackers to execute arbitrary code or cause a denial of service (integer overflow, uninitialized memory access, and use of arbitrary destructor function pointers) via crafted serialized data.  Assigned (20170111)  None (candidate not yet proposed)    View
102159  CVE-2017-5339  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.  Assigned (20170110)  None (candidate not yet proposed)    View
102158  CVE-2017-5338  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.  Assigned (20170110)  None (candidate not yet proposed)    View
102157  CVE-2017-5337  Candidate  Multiple heap-based buffer overflows in the read_attribute function in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allow remote attackers to have unspecified impact via a crafted OpenPGP certificate.  Assigned (20170110)  None (candidate not yet proposed)    View
102156  CVE-2017-5336  Candidate  Stack-based buffer overflow in the cdk_pk_get_keyid function in lib/opencdk/pubkey.c in GnuTLS before 3.3.26 and 3.5.x before 3.5.8 allows remote attackers to have unspecified impact via a crafted OpenPGP certificate.  Assigned (20170110)  None (candidate not yet proposed)    View

Page 512 of 20943, showing 5 records out of 104715 total, starting on record 2556, ending on 2560

Actions