CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93961  CVE-2016-7141  Candidate  curl and libcurl before 7.50.2, when built with NSS and the libnsspem.so library is available at runtime, allow remote attackers to hijack the authentication of a TLS connection by leveraging reuse of a previously loaded client certificate from file for a connection for which no certificate has been set, a different vulnerability than CVE-2016-5420.  Assigned (20160905)  None (candidate not yet proposed)    View
93962  CVE-2016-7142  Candidate  The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.  Assigned (20160905)  None (candidate not yet proposed)    View
93963  CVE-2016-7143  Candidate  The m_authenticate function in modules/m_sasl.c in Charybdis before 3.5.3 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.  Assigned (20160905)  None (candidate not yet proposed)    View
93964  CVE-2016-7144  Candidate  The m_authenticate function in modules/m_sasl.c in UnrealIRCd before 3.2.10.7 and 4.x before 4.0.6 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.  Assigned (20160905)  None (candidate not yet proposed)    View
93965  CVE-2016-7145  Candidate  The m_authenticate function in ircd/m_authenticate.c in nefarious2 allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted AUTHENTICATE parameter.  Assigned (20160905)  None (candidate not yet proposed)    View

Page 18793 of 20943, showing 5 records out of 104715 total, starting on record 93961, ending on 93965

Actions