CVE List

Id CVE No. Status Description Phase Votes Comments Actions
103326  CVE-2017-6506  Candidate  In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string.  Assigned (20170306)  None (candidate not yet proposed)    View
87759  CVE-2016-10244  Candidate  The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file.  Assigned (20170306)  None (candidate not yet proposed)    View
103298  CVE-2017-6478  Candidate  paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).  Assigned (20170305)  None (candidate not yet proposed)    View
103299  CVE-2017-6479  Candidate  FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter).  Assigned (20170305)  None (candidate not yet proposed)    View
103300  CVE-2017-6480  Candidate  groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).  Assigned (20170305)  None (candidate not yet proposed)    View

Page 885 of 20943, showing 5 records out of 104715 total, starting on record 4421, ending on 4425

Actions