CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
87844 | CVE-2016-10321 | Candidate | web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks. | Assigned (20170410) | None (candidate not yet proposed) | View | |
87845 | CVE-2016-10322 | Candidate | Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php. | Assigned (20170410) | None (candidate not yet proposed) | View | |
87846 | CVE-2016-10323 | Candidate | Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command. | Assigned (20170410) | None (candidate not yet proposed) | View | |
104436 | CVE-2017-7616 | Candidate | Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap operation. | Assigned (20170410) | None (candidate not yet proposed) | View | |
104437 | CVE-2017-7617 | Candidate | Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action. | Assigned (20170410) | None (candidate not yet proposed) | View |
Page 635 of 20943, showing 5 records out of 104715 total, starting on record 3171, ending on 3175