CVE List

Id CVE No. Status Description Phase Votes Comments Actions
45844  CVE-2010-3260  Candidate  oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in the XForms service in Orbeon Forms before 3.9 does not properly restrict DTDs in Ajax requests, which allows remote attackers to read arbitrary files or send HTTP requests to intranet servers via an entity declaration in conjunction with an entity reference, related to an "XML injection" issue.  Assigned (20100907)  None (candidate not yet proposed)    View
46100  CVE-2010-3516  Candidate  Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect availability via unknown vectors related to InfiniBand.  Assigned (20100920)  None (candidate not yet proposed)    View
46356  CVE-2010-3772  Candidate  Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child content in a XUL tree, which allows remote attackers to execute arbitrary code via vectors involving a DIV element within a treechildren element.  Assigned (20101005)  None (candidate not yet proposed)    View
46612  CVE-2010-4028  Candidate  Unspecified vulnerability in LoadRunner Web Tours 9.10 in HP LoadRunner 9.1 and earlier allows remote attackers to cause a denial of service, and possibly obtain sensitive information or modify data, via unknown vectors.  Assigned (20101021)  None (candidate not yet proposed)    View
46868  CVE-2010-4284  Candidate  SQL injection vulnerability in the authentication form in the integrated web server in the Data Management Server (DMS) before 1.4.3 in Samsung Integrated Management System allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20101117)  None (candidate not yet proposed)    View

Page 1677 of 20943, showing 5 records out of 104715 total, starting on record 8381, ending on 8385

Actions