CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87844  CVE-2016-10321  Candidate  web2py before 2.14.6 does not properly check if a host is denied before verifying passwords, allowing a remote attacker to perform brute-force attacks.  Assigned (20170410)  None (candidate not yet proposed)    View
87845  CVE-2016-10322  Candidate  Synology Photo Station before 6.3-2958 allows remote authenticated guest users to execute arbitrary commands via shell metacharacters in the X-Forwarded-For HTTP header to photo/login.php.  Assigned (20170410)  None (candidate not yet proposed)    View
87846  CVE-2016-10323  Candidate  Synology Photo Station before 6.3-2958 allows local users to gain privileges by leveraging setuid execution of a "synophoto_dsm_user --copy-no-ea" command.  Assigned (20170410)  None (candidate not yet proposed)    View
104436  CVE-2017-7616  Candidate  Incorrect error handling in the set_mempolicy and mbind compat syscalls in mm/mempolicy.c in the Linux kernel through 4.10.9 allows local users to obtain sensitive information from uninitialized stack data by triggering failure of a certain bitmap operation.  Assigned (20170410)  None (candidate not yet proposed)    View
104437  CVE-2017-7617  Candidate  Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action.  Assigned (20170410)  None (candidate not yet proposed)    View

Page 635 of 20943, showing 5 records out of 104715 total, starting on record 3171, ending on 3175

Actions