CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
39931 | CVE-2009-2496 | Candidate | Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption Vulnerability." | Assigned (20090717) | None (candidate not yet proposed) | View | |
40187 | CVE-2009-2752 | Candidate | IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms. | Assigned (20090812) | None (candidate not yet proposed) | View | |
40443 | CVE-2009-3008 | Candidate | K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker. | Assigned (20090828) | None (candidate not yet proposed) | View | |
40699 | CVE-2009-3264 | Candidate | The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user"s visit to a different web server that hosts an SVG document. | Assigned (20090918) | None (candidate not yet proposed) | View | |
40955 | CVE-2009-3520 | Candidate | Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of administrators for requests that change an administrator password via the pseudo, pwd, and uid parameters in an admin_info_user_verif action. | Assigned (20091001) | None (candidate not yet proposed) | View |
Page 19995 of 20943, showing 5 records out of 104715 total, starting on record 99971, ending on 99975