CVE List

Id CVE No. Status Description Phase Votes Comments Actions
77806  CVE-2015-0543  Candidate  EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141217)  None (candidate not yet proposed)    View
12526  CVE-2005-1320  Candidate  Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent"s frame page title.  Assigned (20050427)  None (candidate not yet proposed)    View
78062  CVE-2015-0799  Candidate  The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.  Assigned (20150107)  None (candidate not yet proposed)    View
12782  CVE-2005-1576  Candidate  The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.  Assigned (20050514)  None (candidate not yet proposed)    View
78318  CVE-2015-1041  Candidate  Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107_files/ file path in the QUERY_STRING.  Assigned (20150111)  None (candidate not yet proposed)    View

Page 18918 of 20943, showing 5 records out of 104715 total, starting on record 94586, ending on 94590

Actions