CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78097  CVE-2015-0834  Candidate  The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.  Assigned (20150107)  None (candidate not yet proposed)    View
12817  CVE-2005-1611  Candidate  Cross-site scripting (XSS) vulnerability in WebX in Web Crossing 5.x allows remote attackers to inject arbitrary web script or HTML via a URL with an "@" followed by the desired script.  Assigned (20050516)  None (candidate not yet proposed)    View
78353  CVE-2015-1076  Candidate  WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1.  Assigned (20150116)  None (candidate not yet proposed)    View
13073  CVE-2005-1867  Candidate  Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges.  Assigned (20050608)  None (candidate not yet proposed)    View
78609  CVE-2015-1332  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150122)  None (candidate not yet proposed)    View

Page 1362 of 20943, showing 5 records out of 104715 total, starting on record 6806, ending on 6810

Actions