CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
77806 | CVE-2015-0543 | Candidate | EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | Assigned (20141217) | None (candidate not yet proposed) | View | |
12526 | CVE-2005-1320 | Candidate | Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent"s frame page title. | Assigned (20050427) | None (candidate not yet proposed) | View | |
78062 | CVE-2015-0799 | Candidate | The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header. | Assigned (20150107) | None (candidate not yet proposed) | View | |
12782 | CVE-2005-1576 | Candidate | The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files. | Assigned (20050514) | None (candidate not yet proposed) | View | |
78318 | CVE-2015-1041 | Candidate | Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107_files/ file path in the QUERY_STRING. | Assigned (20150111) | None (candidate not yet proposed) | View |
Page 18918 of 20943, showing 5 records out of 104715 total, starting on record 94586, ending on 94590