CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93856  CVE-2016-7036  Candidate  python-jose before 1.3.2 allows attackers to have unspecified impact by leveraging failure to use a constant time comparison for HMAC keys.  Assigned (20160823)  None (candidate not yet proposed)    View
93857  CVE-2016-7037  Candidate  The verify function in Encryption/Symmetric.php in Malcolm Fell jwt before 1.0.3 does not use a timing-safe function for hash comparison, which allows attackers to spoof signatures via a timing attack.  Assigned (20160823)  None (candidate not yet proposed)    View
93858  CVE-2016-7038  Candidate  In Moodle 2.x and 3.x, web service tokens are not invalidated when the user password is changed or forced to be changed.  Assigned (20160823)  None (candidate not yet proposed)    View
93859  CVE-2016-7039  Candidate  The IP stack in the Linux kernel through 4.8.2 allows remote attackers to cause a denial of service (stack consumption and panic) or possibly have unspecified other impact by triggering use of the GRO path for large crafted packets, as demonstrated by packets that contain only VLAN headers, a related issue to CVE-2016-8666.  Assigned (20160823)  None (candidate not yet proposed)    View
93860  CVE-2016-7040  Candidate  Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to execute arbitrary shell commands by leveraging the ability to view and filter collections.  Assigned (20160823)  None (candidate not yet proposed)    View

Page 18772 of 20943, showing 5 records out of 104715 total, starting on record 93856, ending on 93860

Actions