CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
77552 | CVE-2015-0289 | Candidate | The PKCS#7 implementation in OpenSSL before 0.9.8zf, 1.0.0 before 1.0.0r, 1.0.1 before 1.0.1m, and 1.0.2 before 1.0.2a does not properly handle a lack of outer ContentInfo, which allows attackers to cause a denial of service (NULL pointer dereference and application crash) by leveraging an application that processes arbitrary PKCS#7 data and providing malformed data with ASN.1 encoding, related to crypto/pkcs7/pk7_doit.c and crypto/pkcs7/pk7_lib.c. | Assigned (20141118) | None (candidate not yet proposed) | View | |
12272 | CVE-2005-1066 | Candidate | Race condition in rpdump in Pine 4.62 and earlier allows local users to overwrite arbitrary files via a symlink attack. | Assigned (20050412) | None (candidate not yet proposed) | View | |
77808 | CVE-2015-0545 | Candidate | EMC Unisphere for VMAX 8.x before 8.0.3.4 sets up the Java Debugging Wire Protocol (JDWP) service, which allows remote attackers to execute arbitrary code via unspecified vectors. | Assigned (20141217) | None (candidate not yet proposed) | View | |
12528 | CVE-2005-1322 | Candidate | Cross-site scripting (XSS) vulnerability in Horde Nag Task List Manager before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via the parent"s frame page title. | Assigned (20050427) | None (candidate not yet proposed) | View | |
78064 | CVE-2015-0801 | Candidate | Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818. | Assigned (20150107) | None (candidate not yet proposed) | View |
Page 19688 of 20943, showing 5 records out of 104715 total, starting on record 98436, ending on 98440