CVE List

Id CVE No. Status Description Phase Votes Comments Actions
45331  CVE-2010-2747  Candidate  Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."  Assigned (20100714)  None (candidate not yet proposed)    View
45587  CVE-2010-3003  Candidate  Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20100813)  None (candidate not yet proposed)    View
45843  CVE-2010-3259  Candidate  WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.  Assigned (20100907)  None (candidate not yet proposed)    View
46099  CVE-2010-3515  Candidate  Unspecified vulnerability in the Solaris component in Oracle Solaris 9 and 10, and OpenSolaris, allows local users to affect availability via unknown vectors related to Kernel/Disk Driver.  Assigned (20100920)  None (candidate not yet proposed)    View
46355  CVE-2010-3771  Candidate  Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.  Assigned (20101005)  None (candidate not yet proposed)    View

Page 1562 of 20943, showing 5 records out of 104715 total, starting on record 7806, ending on 7810

Actions