CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104124  CVE-2017-7304  Candidate  The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, is vulnerable to an invalid read (of size 8) because of missing a check (in the copy_special_section_fields function) for an invalid sh_link field before attempting to follow it. This vulnerability causes Binutils utilities like strip to crash.  Assigned (20170329)  None (candidate not yet proposed)    View
104125  CVE-2017-7305  Candidate  ** DISPUTED ** Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct computational logic for a bootloader password; however, this password is optional to meet different customers" needs.  Assigned (20170329)  None (candidate not yet proposed)    View
104126  CVE-2017-7306  Candidate  ** DISPUTED ** Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and the appliance serial number. NOTE: the vendor believes that this does not meet the definition of a vulnerability. The product contains correct computational logic for supporting arbitrary password changes by customers; however, a password change is optional to meet different customers" needs.  Assigned (20170329)  None (candidate not yet proposed)    View
104127  CVE-2017-7307  Candidate  Riverbed RiOS before 9.0.1 does not properly restrict shell access in single-user mode, which makes it easier for physically proximate attackers to obtain root privileges and access decrypted data by replacing the /opt/tms/bin/cli file.  Assigned (20170329)  None (candidate not yet proposed)    View
104128  CVE-2017-7308  Candidate  The packet_set_ring function in net/packet/af_packet.c in the Linux kernel through 4.10.6 does not properly validate certain block-size data, which allows local users to cause a denial of service (overflow) or possibly have unspecified other impact via crafted system calls.  Assigned (20170329)  None (candidate not yet proposed)    View

Page 704 of 20943, showing 5 records out of 104715 total, starting on record 3516, ending on 3520

Actions