CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104008  CVE-2017-7188  Candidate  Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.  Assigned (20170320)  None (candidate not yet proposed)    View
104009  CVE-2017-7189  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170320)  None (candidate not yet proposed)    View
104010  CVE-2017-7190  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170320)  None (candidate not yet proposed)    View
104011  CVE-2017-7191  Candidate  The netjoin processing in Irssi 1.x before 1.0.2 allows attackers to cause a denial of service (use-after-free) and possibly execute arbitrary code via unspecified vectors.  Assigned (20170320)  None (candidate not yet proposed)    View
104012  CVE-2017-7192  Candidate  WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false).  Assigned (20170320)  None (candidate not yet proposed)    View

Page 744 of 20943, showing 5 records out of 104715 total, starting on record 3716, ending on 3720

Actions