CVE List

Id CVE No. Status Description Phase Votes Comments Actions
45075  CVE-2010-2491  Candidate  Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.  Assigned (20100628)  None (candidate not yet proposed)    View
45331  CVE-2010-2747  Candidate  Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."  Assigned (20100714)  None (candidate not yet proposed)    View
45587  CVE-2010-3003  Candidate  Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20100813)  None (candidate not yet proposed)    View
45843  CVE-2010-3259  Candidate  WebKit, as used in Apple Safari before 4.1.3 and 5.0.x before 5.0.3, Google Chrome before 6.0.472.53, and webkitgtk before 1.2.6, does not properly restrict read access to images derived from CANVAS elements, which allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive image data via a crafted web site.  Assigned (20100907)  None (candidate not yet proposed)    View
46099  CVE-2010-3515  Candidate  Unspecified vulnerability in the Solaris component in Oracle Solaris 9 and 10, and OpenSolaris, allows local users to affect availability via unknown vectors related to Kernel/Disk Driver.  Assigned (20100920)  None (candidate not yet proposed)    View

Page 1575 of 20943, showing 5 records out of 104715 total, starting on record 7871, ending on 7875

Actions