CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104432  CVE-2017-7612  Candidate  The check_sysv_hash function in elflint.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.  Assigned (20170409)  None (candidate not yet proposed)    View
104433  CVE-2017-7613  Candidate  elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.  Assigned (20170409)  None (candidate not yet proposed)    View
104434  CVE-2017-7614  Candidate  elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a "member access within null pointer" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an "int main() {return 0;}" program.  Assigned (20170409)  None (candidate not yet proposed)    View
104435  CVE-2017-7615  Candidate  MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.  Assigned (20170409)  None (candidate not yet proposed)    View
104408  CVE-2017-7588  Candidate  On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW MFC-J4620DW MFC-L8850CDW MFC-J3720 MFC-J6520DW MFC-L2740DW MFC-J5910DW MFC-J6920DW MFC-L2700DW MFC-9130CW MFC-9330CDW MFC-9340CDW MFC-J5620DW MFC-J6720DW MFC-L8600CDW MFC-L9550CDW MFC-L2720DW DCP-L2540DW DCP-L2520DW HL-3140CW HL-3170CDW HL-3180CDW HL-L8350CDW HL-L2380DW ADS-2500W ADS-1000W ADS-1500W.  Assigned (20170408)  None (candidate not yet proposed)    View

Page 642 of 20943, showing 5 records out of 104715 total, starting on record 3206, ending on 3210

Actions