CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93973  CVE-2016-7153  Candidate  The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.  Assigned (20160906)  None (candidate not yet proposed)    View
28693  CVE-2007-5336  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2007-5339. Reason: This candidate is a reservation duplicate of CVE-2007-5339. Notes: All CVE users should reference CVE-2007-5339 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20071010)  None (candidate not yet proposed)    View
94229  CVE-2016-7409  Candidate  The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.  Assigned (20160909)  None (candidate not yet proposed)    View
28949  CVE-2007-5592  Candidate  Multiple PHP remote file inclusion vulnerabilities in awzMB 4.2 beta 1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the Setting[OPT_includepath] parameter to (1) adminhelp.php; and (2) admin.incl.php, (3) reg.incl.php, (4) help.incl.php, (5) gbook.incl.php, and (6) core/core.incl.php in modules/.  Assigned (20071019)  None (candidate not yet proposed)    View
94485  CVE-2016-7665  Candidate  An issue was discovered in certain Apple products. iOS before 10.2 is affected. The issue involves the "Graphics Driver" component, which allows remote attackers to cause a denial of service via a crafted video.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 1713 of 20943, showing 5 records out of 104715 total, starting on record 8561, ending on 8565

Actions