CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42763  CVE-2010-0179  Candidate  Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.  Assigned (20100106)  None (candidate not yet proposed)    View
43019  CVE-2010-0435  Candidate  The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2, and KVM 83, when the Intel VT-x extension is enabled, allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via vectors related to instruction emulation.  Assigned (20100127)  None (candidate not yet proposed)    View
43275  CVE-2010-0691  Candidate  SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands via the s parameter.  Assigned (20100223)  None (candidate not yet proposed)    View
43531  CVE-2010-0947  Candidate  Cross-site scripting (XSS) vulnerability in post.aspx in Max Network Technology BBSMAX 3.0, 4.1, and 4.2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.  Assigned (20100309)  None (candidate not yet proposed)    View
43787  CVE-2010-1203  Candidate  The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.  Assigned (20100330)  None (candidate not yet proposed)    View

Page 1551 of 20943, showing 5 records out of 104715 total, starting on record 7751, ending on 7755

Actions