CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43543  CVE-2010-0959  Candidate  Cross-site scripting (XSS) vulnerability in WebEditor/Authentication/LoginPage.aspx in IBM ENOVIA SmarTeam 5 allows remote attackers to inject arbitrary web script or HTML via the errMsg parameter.  Assigned (20100310)  None (candidate not yet proposed)    View
43799  CVE-2010-1215  Candidate  Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."  Assigned (20100330)  None (candidate not yet proposed)    View
44055  CVE-2010-1471  Candidate  Directory traversal vulnerability in the AddressBook (com_addressbook) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.  Assigned (20100419)  None (candidate not yet proposed)    View
44311  CVE-2010-1727  Candidate  SQL injection vulnerability in type.asp in JobPost 1.0 allows remote attackers to execute arbitrary SQL commands via the iType parameter. NOTE: some of these details are obtained from third party information.  Assigned (20100505)  None (candidate not yet proposed)    View
44567  CVE-2010-1983  Candidate  Directory traversal vulnerability in the redTWITTER (com_redtwitter) component 1.0.x including 1.0b11 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter to index.php. NOTE: some of these details are obtained from third party information.  Assigned (20100519)  None (candidate not yet proposed)    View

Page 1892 of 20943, showing 5 records out of 104715 total, starting on record 9456, ending on 9460

Actions