CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42767  CVE-2010-0183  Candidate  Use-after-free vulnerability in the nsCycleCollector::MarkRoots function in Mozilla Firefox 3.5.x before 3.5.10 and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a crafted HTML document, related to an improper frame construction process for menus.  Assigned (20100106)  None (candidate not yet proposed)    View
43023  CVE-2010-0439  Candidate  Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on an unspecified file.  Assigned (20100127)  None (candidate not yet proposed)    View
43279  CVE-2010-0695  Candidate  Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter.  Assigned (20100223)  None (candidate not yet proposed)    View
43535  CVE-2010-0951  Candidate  SQL injection vulnerability in go_target.php in dev4u CMS allows remote attackers to execute arbitrary SQL commands via the kontent_id parameter.  Assigned (20100309)  None (candidate not yet proposed)    View
43791  CVE-2010-1207  Candidate  Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.  Assigned (20100330)  None (candidate not yet proposed)    View

Page 1272 of 20943, showing 5 records out of 104715 total, starting on record 6356, ending on 6360

Actions