CVE List

Id CVE No. Status Description Phase Votes Comments Actions
77551  CVE-2015-0288  Candidate  The X509_to_X509_REQ function in crypto/x509/x509_req.c in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a might allow attackers to cause a denial of service (NULL pointer dereference and application crash) via an invalid certificate key.  Assigned (20141118)  None (candidate not yet proposed)    View
12271  CVE-2005-1065  Candidate  tetex in Novell Linux Desktop 9 allows local users to determine the existence of arbitrary files via a symlink attack in the /var/cache/fonts directory.  Assigned (20050412)  None (candidate not yet proposed)    View
77807  CVE-2015-0544  Candidate  EMC Secure Remote Services Virtual Edition (ESRS VE) 3.x before 3.06 does not properly generate random values for session cookies, which makes it easier for remote attackers to hijack sessions by predicting a value.  Assigned (20141217)  None (candidate not yet proposed)    View
12527  CVE-2005-1321  Candidate  Cross-site scripting (XSS) vulnerability in Horde Vacation module before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via the parent"s frame page title.  Assigned (20050427)  None (candidate not yet proposed)    View
78063  CVE-2015-0800  Candidate  The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2012-2808.  Assigned (20150107)  None (candidate not yet proposed)    View

Page 19608 of 20943, showing 5 records out of 104715 total, starting on record 98036, ending on 98040

Actions