CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
67602 | CVE-2014-0193 | Candidate | WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a TextWebSocketFrame followed by a long stream of ContinuationWebSocketFrames. | Assigned (20131203) | None (candidate not yet proposed) | View | |
102707 | CVE-2017-5887 | Candidate | WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function). | Assigned (20170206) | None (candidate not yet proposed) | View | |
104012 | CVE-2017-7192 | Candidate | WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false). | Assigned (20170320) | None (candidate not yet proposed) | View | |
1644 | CVE-2000-0066 | Candidate | WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request. | Proposed (20000125) | ACCEPT(2) Baker, Williams | MODIFY(1) Frech | NOOP(1) Christey | Frech> XF:website-pro-dir-path | Christey> ADDREF BUGTRAQ:20000113 Re: WebSitePro/2.3.18 + 2.4.9 is revealing Webdirectories | URL:http://www.securityfocus.com/archive/1/41798 | Also BID:932 | View |
6795 | CVE-2002-2413 | Candidate | WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name. | Assigned (20071101) | None (candidate not yet proposed) | View |
Page 233 of 20943, showing 5 records out of 104715 total, starting on record 1161, ending on 1165