CVE List

Id CVE No. Status Description Phase Votes Comments Actions
44043  CVE-2010-1459  Candidate  The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.  Assigned (20100416)  None (candidate not yet proposed)    View
44299  CVE-2010-1715  Candidate  Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.  Assigned (20100504)  None (candidate not yet proposed)    View
44555  CVE-2010-1971  Candidate  Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1968.  Assigned (20100519)  None (candidate not yet proposed)    View
44811  CVE-2010-2227  Candidate  Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."  Assigned (20100609)  None (candidate not yet proposed)    View
45067  CVE-2010-2483  Candidate  The TIFFRGBAImageGet function in LibTIFF 3.9.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a TIFF file with an invalid combination of SamplesPerPixel and Photometric values.  Assigned (20100628)  None (candidate not yet proposed)    View

Page 1552 of 20943, showing 5 records out of 104715 total, starting on record 7756, ending on 7760

Actions