CVE List

Id CVE No. Status Description Phase Votes Comments Actions
93971  CVE-2016-7151  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160905)  None (candidate not yet proposed)    View
93972  CVE-2016-7152  Candidate  The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.  Assigned (20160906)  None (candidate not yet proposed)    View
93973  CVE-2016-7153  Candidate  The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.  Assigned (20160906)  None (candidate not yet proposed)    View
93974  CVE-2016-7154  Candidate  Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number.  Assigned (20160906)  None (candidate not yet proposed)    View
93975  CVE-2016-7155  Candidate  hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings.  Assigned (20160906)  None (candidate not yet proposed)    View

Page 18795 of 20943, showing 5 records out of 104715 total, starting on record 93971, ending on 93975

Actions