CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46836  CVE-2010-4252  Candidate  OpenSSL before 1.0.0c, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol.  Assigned (20101116)  None (candidate not yet proposed)    View
47092  CVE-2010-4508  Candidate  The WebSockets implementation in Mozilla Firefox 4 through 4.0 Beta 7 does not properly perform proxy upgrade negotiation, which has unspecified impact and remote attack vectors, related to an "inherent problem" with the WebSocket specification.  Assigned (20101209)  None (candidate not yet proposed)    View
47348  CVE-2010-4764  Candidate  Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it easier for remote attackers to spoof e-mail communication by leveraging a key that has a revocation signature.  Assigned (20110318)  None (candidate not yet proposed)    View
47604  CVE-2010-5020  Candidate  SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL commands via the page parameter.  Assigned (20111102)  None (candidate not yet proposed)    View
47860  CVE-2010-5276  Candidate  The Memcache module 5.x before 5.x-1.10 and 6.x before 6.x-1.6 for Drupal does not properly handle the $user object in memcache_admin, which might "lead to a role change not being recognized until the user logs in again."  Assigned (20121007)  None (candidate not yet proposed)    View

Page 20054 of 20943, showing 5 records out of 104715 total, starting on record 100266, ending on 100270

Actions