CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38636  CVE-2009-1201  Candidate  Eval injection vulnerability in the csco_wrap_js function in /+CSCOL+/cte.js in WebVPN on the Cisco Adaptive Security Appliances (ASA) device with software 8.0(4), 8.1.2, and 8.2.1 allows remote attackers to bypass a DOM wrapper and conduct cross-site scripting (XSS) attacks by setting CSCO_WebVPN["process"] to the name of a crafted function, aka Bug ID CSCsy80694.  Assigned (20090331)  None (candidate not yet proposed)    View
104172  CVE-2017-7352  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170330)  None (candidate not yet proposed)    View
38892  CVE-2009-1457  Candidate  Cross-site scripting (XSS) vulnerability in player.php in Nuke Evolution Xtreme 2.x allows remote attackers to inject arbitrary web script or HTML via the defaultVisualExt parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20090428)  None (candidate not yet proposed)    View
104428  CVE-2017-7608  Candidate  The ebl_object_note_type_name function in eblobjnotetypename.c in elfutils 0.168 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted ELF file.  Assigned (20170409)  None (candidate not yet proposed)    View
39148  CVE-2009-1713  Candidate  The XSLT functionality in WebKit in Apple Safari before 4.0 does not properly implement the document function, which allows remote attackers to read (1) arbitrary local files and (2) files from different security zones via unspecified vectors.  Assigned (20090520)  None (candidate not yet proposed)    View

Page 19400 of 20943, showing 5 records out of 104715 total, starting on record 96996, ending on 97000

Actions