CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67602  CVE-2014-0193  Candidate  WebSocket08FrameDecoder in Netty 3.6.x before 3.6.9, 3.7.x before 3.7.1, 3.8.x before 3.8.2, 3.9.x before 3.9.1, and 4.0.x before 4.0.19 allows remote attackers to cause a denial of service (memory consumption) via a TextWebSocketFrame followed by a long stream of ContinuationWebSocketFrames.  Assigned (20131203)  None (candidate not yet proposed)    View
102707  CVE-2017-5887  Candidate  WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because pinning occurs in the stream function (this is too late; pinning should occur in the initStreamsWithData function).  Assigned (20170206)  None (candidate not yet proposed)    View
104012  CVE-2017-7192  Candidate  WebSocket.swift in Starscream before 2.0.4 allows an SSL Pinning bypass because of incorrect management of the certValidated variable (it can be set to true but cannot be set to false).  Assigned (20170320)  None (candidate not yet proposed)    View
1644  CVE-2000-0066  Candidate  WebSite Pro allows remote attackers to determine the real pathname of webdirectories via a malformed URL request.  Proposed (20000125)  ACCEPT(2) Baker, Williams | MODIFY(1) Frech | NOOP(1) Christey  Frech> XF:website-pro-dir-path | Christey> ADDREF BUGTRAQ:20000113 Re: WebSitePro/2.3.18 + 2.4.9 is revealing Webdirectories | URL:http://www.securityfocus.com/archive/1/41798 | Also BID:932  View
6795  CVE-2002-2413  Candidate  WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8.3 file name.  Assigned (20071101)  None (candidate not yet proposed)    View

Page 233 of 20943, showing 5 records out of 104715 total, starting on record 1161, ending on 1165

Actions