CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102890 | CVE-2017-6070 | Candidate | CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form. | Assigned (20170217) | None (candidate not yet proposed) | View | |
102891 | CVE-2017-6071 | Candidate | CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml. | Assigned (20170217) | None (candidate not yet proposed) | View | |
102892 | CVE-2017-6072 | Candidate | CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via defaultadmin. | Assigned (20170217) | None (candidate not yet proposed) | View | |
102893 | CVE-2017-6073 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170217) | None (candidate not yet proposed) | View | |
102894 | CVE-2017-6074 | Candidate | The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of service (double free) via an application that makes an IPV6_RECVPKTINFO setsockopt system call. | Assigned (20170217) | None (candidate not yet proposed) | View |
Page 985 of 20943, showing 5 records out of 104715 total, starting on record 4921, ending on 4925