CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38646  CVE-2009-1211  Candidate  Blue Coat ProxySG, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.  Assigned (20090331)  None (candidate not yet proposed)    View
104182  CVE-2017-7362  Candidate  Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.  Assigned (20170330)  None (candidate not yet proposed)    View
38902  CVE-2009-1467  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2) title, (3) link, or (4) description element in an RSS feed, related to the getHTML function in server/inc/rss/item.php.  Assigned (20090428)  None (candidate not yet proposed)    View
104438  CVE-2017-7618  Candidate  crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.  Assigned (20170410)  None (candidate not yet proposed)    View
39158  CVE-2009-1723  Candidate  CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an open redirect vulnerability, a different issue than CVE-2009-2062.  Assigned (20090520)  None (candidate not yet proposed)    View

Page 20192 of 20943, showing 5 records out of 104715 total, starting on record 100956, ending on 100960

Actions