CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13906  CVE-2005-2700  Candidate  ssl_engine_kernel.c in mod_ssl before 2.8.24, when using "SSLVerifyClient optional" in the global virtual host configuration, does not properly enforce "SSLVerifyClient require" in a per-location context, which allows remote attackers to bypass intended access restrictions.  Assigned (20050826)  None (candidate not yet proposed)    View
13907  CVE-2005-2701  Candidate  Heap-based buffer overflow in Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to execute arbitrary code via an XBM image file that ends in a large number of spaces instead of the expected end tag.  Assigned (20050826)  None (candidate not yet proposed)    View
13908  CVE-2005-2702  Candidate  Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via Unicode sequences with "zero-width non-joiner" characters.  Assigned (20050826)  None (candidate not yet proposed)    View
13909  CVE-2005-2703  Candidate  Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to modify HTTP headers of XML HTTP requests via XMLHttpRequest, and possibly use the client to exploit vulnerabilities in servers or proxies, including HTTP request smuggling and HTTP request splitting.  Assigned (20050826)  None (candidate not yet proposed)    View
13910  CVE-2005-2704  Candidate  Firefox before 1.0.7 and Mozilla Suite before 1.7.12 allows remote attackers to spoof DOM objects via an XBL control that implements an internal XPCOM interface.  Assigned (20050826)  None (candidate not yet proposed)    View

Page 18946 of 20943, showing 5 records out of 104715 total, starting on record 94726, ending on 94730

Actions