CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
93971 | CVE-2016-7151 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160905) | None (candidate not yet proposed) | View | |
93972 | CVE-2016-7152 | Candidate | The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack. | Assigned (20160906) | None (candidate not yet proposed) | View | |
93973 | CVE-2016-7153 | Candidate | The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack. | Assigned (20160906) | None (candidate not yet proposed) | View | |
93974 | CVE-2016-7154 | Candidate | Use-after-free vulnerability in the FIFO event channel code in Xen 4.4.x allows local guest OS administrators to cause a denial of service (host crash) and possibly execute arbitrary code or obtain sensitive information via an invalid guest frame number. | Assigned (20160906) | None (candidate not yet proposed) | View | |
93975 | CVE-2016-7155 | Candidate | hw/scsi/vmw_pvscsi.c in QEMU (aka Quick Emulator) allows local guest OS administrators to cause a denial of service (out-of-bounds access or infinite loop, and QEMU process crash) via a crafted page count for descriptor rings. | Assigned (20160906) | None (candidate not yet proposed) | View |
Page 18795 of 20943, showing 5 records out of 104715 total, starting on record 93971, ending on 93975