CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12680  CVE-2005-1474  Candidate  Dashboard in Apple Mac OS X 10.4.1 allows remote attackers to install widgets via Safari without prompting the user, a different vulnerability than CVE-2005-1933.  Assigned (20050509)  None (candidate not yet proposed)    View
12681  CVE-2005-1475  Candidate  The XMLHttpRequest object in Opera 8.0 Final Build 1095 allows remote attackers to bypass access restrictions and perform unauthorized actions on other domains via a redirect.  Assigned (20050509)  None (candidate not yet proposed)    View
12682  CVE-2005-1476  Candidate  Firefox 1.0.3 allows remote attackers to execute arbitrary Javascript in other domains by using an IFRAME and causing the browser to navigate to a previous javascript: URL, which can lead to arbitrary code execution when combined with CVE-2005-1477.  Assigned (20050509)  None (candidate not yet proposed)    View
12683  CVE-2005-1477  Candidate  The install function in Firefox 1.0.3 allows remote web sites on the browser"s whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.  Assigned (20050509)  None (candidate not yet proposed)    View
12678  CVE-2005-1472  Candidate  Certain system calls in Apple Mac OS X 10.4.1 do not properly enforce the permissions of certain directories without the POSIX read bit set, but with the execute bits set for group or other, which allows local users to list files in otherwise restricted directories.  Assigned (20050507)  None (candidate not yet proposed)    View

Page 19397 of 20943, showing 5 records out of 104715 total, starting on record 96981, ending on 96985

Actions