CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104389 | CVE-2017-7569 | Candidate | In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037. | Assigned (20170406) | None (candidate not yet proposed) | View | |
104390 | CVE-2017-7570 | Candidate | PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension. | Assigned (20170406) | None (candidate not yet proposed) | View | |
104391 | CVE-2017-7571 | Candidate | public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges. | Assigned (20170406) | None (candidate not yet proposed) | View | |
104392 | CVE-2017-7572 | Candidate | The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subject to a race condition (time of check, time of use). With this authorization method, the owner of a process requesting a polkit operation is checked by polkitd via /proc/<pid>/status, by which time the requesting process may have been replaced by a different process with the same PID that has different privileges then the original requester. | Assigned (20170406) | None (candidate not yet proposed) | View | |
104393 | CVE-2017-7573 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170406) | None (candidate not yet proposed) | View |
Page 648 of 20943, showing 5 records out of 104715 total, starting on record 3236, ending on 3240