CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
78097 | CVE-2015-0834 | Candidate | The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window. | Assigned (20150107) | None (candidate not yet proposed) | View | |
12817 | CVE-2005-1611 | Candidate | Cross-site scripting (XSS) vulnerability in WebX in Web Crossing 5.x allows remote attackers to inject arbitrary web script or HTML via a URL with an "@" followed by the desired script. | Assigned (20050516) | None (candidate not yet proposed) | View | |
78353 | CVE-2015-1076 | Candidate | WebKit, as used in Apple Safari before 6.2.4, 7.x before 7.1.4, and 8.x before 8.0.4, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other CVEs listed in APPLE-SA-2015-03-17-1. | Assigned (20150116) | None (candidate not yet proposed) | View | |
13073 | CVE-2005-1867 | Candidate | Symantec Brightmail AntiSpam before 6.0.2 has a hard-coded database administrator password, which allows remote attackers to gain privileges. | Assigned (20050608) | None (candidate not yet proposed) | View | |
78609 | CVE-2015-1332 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20150122) | None (candidate not yet proposed) | View |
Page 1362 of 20943, showing 5 records out of 104715 total, starting on record 6806, ending on 6810