CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
103326 | CVE-2017-6506 | Candidate | In Azure Data Expert Ultimate 2.2.16, the SMTP verification function suffers from a buffer overflow vulnerability, leading to remote code execution. The attack vector is a crafted SMTP daemon that sends a long 220 (aka "Service ready") string. | Assigned (20170306) | None (candidate not yet proposed) | View | |
87759 | CVE-2016-10244 | Candidate | The parse_charstrings function in type1/t1load.c in FreeType 2 before 2.7 does not ensure that a font contains a glyph name, which allows remote attackers to cause a denial of service (heap-based buffer over-read) or possibly have unspecified other impact via a crafted file. | Assigned (20170306) | None (candidate not yet proposed) | View | |
103298 | CVE-2017-6478 | Candidate | paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter). | Assigned (20170305) | None (candidate not yet proposed) | View | |
103299 | CVE-2017-6479 | Candidate | FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter). | Assigned (20170305) | None (candidate not yet proposed) | View | |
103300 | CVE-2017-6480 | Candidate | groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter). | Assigned (20170305) | None (candidate not yet proposed) | View |
Page 885 of 20943, showing 5 records out of 104715 total, starting on record 4421, ending on 4425