CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67319  CVE-2013-7372  Candidate  The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom implementation in Apache Harmony through 6.0M3, as used in the Java Cryptography Architecture (JCA) in Android before 4.4 and other products, when no seed is provided by the user, uses an incorrect offset value, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging the resulting PRNG predictability, as exploited in the wild against Bitcoin wallet applications in August 2013.  Assigned (20140429)  None (candidate not yet proposed)    View
67575  CVE-2014-0166  Candidate  The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie.  Assigned (20131203)  None (candidate not yet proposed)    View
2295  CVE-2000-0719  Candidate  VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program.  Proposed (20000921)  MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Williams | REVIEWING(1) Levy  Christey> XF:varicad-world-write-permissions | http://xforce.iss.net/static/5077.php | Frech> XF:aricad-world-write-permissions(5077) | Christey> BID:1862  View
67831  CVE-2014-0422  Candidate  Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JNDI. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to missing package access checks in the Naming / JNDI component, which allows attackers to escape the sandbox.  Assigned (20131212)  None (candidate not yet proposed)    View
68087  CVE-2014-0678  Candidate  The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack sessions and gain privileges via unspecified vectors, aka Bug ID CSCue65951.  Assigned (20140102)  None (candidate not yet proposed)    View

Page 20230 of 20943, showing 5 records out of 104715 total, starting on record 101146, ending on 101150

Actions