CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
45844 | CVE-2010-3260 | Candidate | oxf/xml/xerces/XercesSAXParserFactoryImpl.java in the xforms-server component in the XForms service in Orbeon Forms before 3.9 does not properly restrict DTDs in Ajax requests, which allows remote attackers to read arbitrary files or send HTTP requests to intranet servers via an entity declaration in conjunction with an entity reference, related to an "XML injection" issue. | Assigned (20100907) | None (candidate not yet proposed) | View | |
46100 | CVE-2010-3516 | Candidate | Unspecified vulnerability in Oracle Solaris 10 and OpenSolaris allows local users to affect availability via unknown vectors related to InfiniBand. | Assigned (20100920) | None (candidate not yet proposed) | View | |
46356 | CVE-2010-3772 | Candidate | Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child content in a XUL tree, which allows remote attackers to execute arbitrary code via vectors involving a DIV element within a treechildren element. | Assigned (20101005) | None (candidate not yet proposed) | View | |
46612 | CVE-2010-4028 | Candidate | Unspecified vulnerability in LoadRunner Web Tours 9.10 in HP LoadRunner 9.1 and earlier allows remote attackers to cause a denial of service, and possibly obtain sensitive information or modify data, via unknown vectors. | Assigned (20101021) | None (candidate not yet proposed) | View | |
46868 | CVE-2010-4284 | Candidate | SQL injection vulnerability in the authentication form in the integrated web server in the Data Management Server (DMS) before 1.4.3 in Samsung Integrated Management System allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Assigned (20101117) | None (candidate not yet proposed) | View |
Page 1677 of 20943, showing 5 records out of 104715 total, starting on record 8381, ending on 8385