CVE List

Id CVE No. Status Description Phase Votes Comments Actions
77550  CVE-2015-0287  Candidate  The ASN1_item_ex_d2i function in crypto/asn1/tasn_dec.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not reinitialize CHOICE and ADB data structures, which might allow attackers to cause a denial of service (invalid write operation and memory corruption) by leveraging an application that relies on ASN.1 structure reuse.  Assigned (20141118)  None (candidate not yet proposed)    View
12270  CVE-2005-1064  Candidate  The copy_symlink function in rsnapshot 1.2.0 and 1.1.x before 1.1.7 changes the ownership of files that a symlink points to rather than the symlink itself, which allows local users to obtain access to arbitrary files.  Assigned (20050412)  None (candidate not yet proposed)    View
77806  CVE-2015-0543  Candidate  EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20141217)  None (candidate not yet proposed)    View
12526  CVE-2005-1320  Candidate  Cross-site scripting (XSS) vulnerability in Horde Mnemo Note Manager before 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the parent"s frame page title.  Assigned (20050427)  None (candidate not yet proposed)    View
78062  CVE-2015-0799  Candidate  The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.  Assigned (20150107)  None (candidate not yet proposed)    View

Page 19534 of 20943, showing 5 records out of 104715 total, starting on record 97666, ending on 97670

Actions