NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88200 | CVE-2017-8932 | A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
58760 | CVE-2006-0014 | Buffer overflow in Microsoft Outlook Express 5.5 and 6 allows remote attackers to execute arbitrary code via a crafted Windows Address Book (WAB) file containing "certain Unicode strings" and modified length values. | 2 | 5.1 | Medium | 2017-07-18 | 2017-07-10 | View | |
66185 | CVE-2005-0427 | The ebuild of Webmin before 1.170-r3 on Gentoo Linux includes the encrypted root password in the miniserv.users file when building a tbz2 of the webmin package, which allows remote attackers to obtain and possibly crack the encrypted password. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
66697 | CVE-2005-0948 | SQL injection vulnerability in ad_click.asp for PortalApp allows remote attackers to execute arbitrary SQL commands via the banner_id parameter. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
67977 | CVE-2005-2276 | Cross-site scripting (XSS) vulnerability in Novell Groupwise WebAccess 6.5 before July 11, 2005 allows remote attackers to inject arbitrary web script or HTML via an e-mail message with an encoded javascript URI (e.g. "jAvascript" in an IMG tag. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View |
Page 17031 of 17672, showing 5 records out of 88360 total, starting on record 85151, ending on 85155