CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
77551 | CVE-2015-0288 | Candidate | The X509_to_X509_REQ function in crypto/x509/x509_req.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow attackers to cause a denial of service (NULL pointer dereference and application crash) via an invalid certificate key. | Assigned (20141118) | None (candidate not yet proposed) | View | |
12271 | CVE-2005-1065 | Candidate | tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory. | Assigned (20050412) | None (candidate not yet proposed) | View | |
77807 | CVE-2015-0544 | Candidate | EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value. | Assigned (20141217) | None (candidate not yet proposed) | View | |
12527 | CVE-2005-1321 | Candidate | Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent"s frame page title. | Assigned (20050427) | None (candidate not yet proposed) | View | |
78063 | CVE-2015-0800 | Candidate | The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2012-2808. | Assigned (20150107) | None (candidate not yet proposed) | View |
Page 19608 of 20943, showing 5 records out of 104715 total, starting on record 98036, ending on 98040