CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13906 | CVE-2005-2700 | Candidate | ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions. | Assigned (20050826) | None (candidate not yet proposed) | View | |
13907 | CVE-2005-2701 | Candidate | Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag. | Assigned (20050826) | None (candidate not yet proposed) | View | |
13908 | CVE-2005-2702 | Candidate | Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters. | Assigned (20050826) | None (candidate not yet proposed) | View | |
13909 | CVE-2005-2703 | Candidate | Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting. | Assigned (20050826) | None (candidate not yet proposed) | View | |
13910 | CVE-2005-2704 | Candidate | Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface. | Assigned (20050826) | None (candidate not yet proposed) | View |
Page 18946 of 20943, showing 5 records out of 104715 total, starting on record 94726, ending on 94730