CVE List

Id CVE No. Status Description Phase Votes Comments Actions
6395  CVE-2002-2013  Candidate  Mozilla 0.9.6 and earlier and Netscape 6.2 and earlier allows remote attackers to steal cookies from another domain via a link with a hex-encoded null character (%00) followed by the target domain.  Assigned (20050714)  None (candidate not yet proposed)    View
71931  CVE-2014-4634  Candidate  Unquoted Windows search path vulnerability in EMC Replication Manager through 5.5.2 and AppSync before 2.1.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character.  Assigned (20140624)  None (candidate not yet proposed)    View
6651  CVE-2002-2269  Candidate  Directory traversal vulnerability in Webster HTTP Server allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.  Assigned (20071017)  None (candidate not yet proposed)    View
72187  CVE-2014-4890  Candidate  The Nano Digest (aka com.magzter.nanodigest) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20140710)  None (candidate not yet proposed)    View
6907  CVE-2003-0078  Entry  ssl3_get_record in s3_pkt.c for OpenSSL before 0.9.7a and 0.9.6 before 0.9.6i does not perform a MAC computation if an incorrect block cipher padding is used, which causes an information leak (timing discrepancy) that may make it easier to launch cryptographic attacks that rely on distinguishing between padding and MAC verification errors, possibly leading to extraction of the original plaintext, aka the "Vaudenay timing attack."        View

Page 20551 of 20943, showing 5 records out of 104715 total, starting on record 102751, ending on 102755

Actions