CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104389  CVE-2017-7569  Candidate  In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.  Assigned (20170406)  None (candidate not yet proposed)    View
104390  CVE-2017-7570  Candidate  PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension.  Assigned (20170406)  None (candidate not yet proposed)    View
104391  CVE-2017-7571  Candidate  public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.  Assigned (20170406)  None (candidate not yet proposed)    View
104392  CVE-2017-7572  Candidate  The _checkPolkitPrivilege function in serviceHelper.py in Back In Time (aka backintime) 1.1.18 and earlier uses a deprecated polkit authorization method (unix-process) that is subject to a race condition (time of check, time of use). With this authorization method, the owner of a process requesting a polkit operation is checked by polkitd via /proc/<pid>/status, by which time the requesting process may have been replaced by a different process with the same PID that has different privileges then the original requester.  Assigned (20170406)  None (candidate not yet proposed)    View
104393  CVE-2017-7573  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170406)  None (candidate not yet proposed)    View

Page 648 of 20943, showing 5 records out of 104715 total, starting on record 3236, ending on 3240

Actions