CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102411 | CVE-2017-5591 | Candidate | An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for SleekXMPP up to 1.3.1 and Slixmpp all versions up to 1.2.3, as bundled in poezio (0.8 - 0.10) and other products. | Assigned (20170125) | None (candidate not yet proposed) | View | |
37131 | CVE-2008-7014 | Candidate | fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an invalid character after the Basic value. | Assigned (20090818) | None (candidate not yet proposed) | View | |
102667 | CVE-2017-5847 | Candidate | The gst_asf_demux_process_ext_content_desc function in gst/asfdemux/gstasfdemux.c in gst-plugins-ugly in GStreamer allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving extended content descriptors. | Assigned (20170201) | None (candidate not yet proposed) | View | |
37387 | CVE-2008-7270 | Candidate | OpenSSL before 0.9.8j, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the use of a disabled cipher via vectors involving sniffing network traffic to discover a session identifier, a different vulnerability than CVE-2010-4180. | Assigned (20101206) | None (candidate not yet proposed) | View | |
102923 | CVE-2017-6103 | Candidate | Persistent XSS Vulnerability in Wordpress plugin AnyVar v0.1.1. | Assigned (20170221) | None (candidate not yet proposed) | View |
Page 934 of 20943, showing 5 records out of 104715 total, starting on record 4666, ending on 4670