CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
67319 | CVE-2013-7372 | Candidate | The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom implementation in Apache Harmony through 6.0M3, as used in the Java Cryptography Architecture (JCA) in Android before 4.4 and other products, when no seed is provided by the user, uses an incorrect offset value, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging the resulting PRNG predictability, as exploited in the wild against Bitcoin wallet applications in August 2013. | Assigned (20140429) | None (candidate not yet proposed) | View | |
67575 | CVE-2014-0166 | Candidate | The wp_validate_auth_cookie function in wp-includes/pluggable.php in WordPress before 3.7.2 and 3.8.x before 3.8.2 does not properly determine the validity of authentication cookies, which makes it easier for remote attackers to obtain access via a forged cookie. | Assigned (20131203) | None (candidate not yet proposed) | View | |
2295 | CVE-2000-0719 | Candidate | VariCAD 7.0 is installed with world-writeable files, which allows local users to replace the VariCAD programs with a Trojan horse program. | Proposed (20000921) | MODIFY(1) Frech | NOOP(4) Christey, Cole, Wall, Williams | REVIEWING(1) Levy | Christey> XF:varicad-world-write-permissions | http://xforce.iss.net/static/5077.php | Frech> XF:aricad-world-write-permissions(5077) | Christey> BID:1862 | View |
67831 | CVE-2014-0422 | Candidate | Unspecified vulnerability in Oracle Java SE 5.0u55, 6u65, and 7u45; Java SE Embedded 7u45; and OpenJDK 7 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JNDI. NOTE: the previous information is from the January 2014 CPU. Oracle has not commented on third-party claims that the issue is related to missing package access checks in the Naming / JNDI component, which allows attackers to escape the sandbox. | Assigned (20131212) | None (candidate not yet proposed) | View | |
68087 | CVE-2014-0678 | Candidate | The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack sessions and gain privileges via unspecified vectors, aka Bug ID CSCue65951. | Assigned (20140102) | None (candidate not yet proposed) | View |
Page 20230 of 20943, showing 5 records out of 104715 total, starting on record 101146, ending on 101150