CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42746  CVE-2010-0162  Candidate  Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, does not properly support the application/octet-stream content type as a protection mechanism against execution of web script in certain circumstances involving SVG and the EMBED element, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via an embedded SVG document.  Assigned (20100106)  None (candidate not yet proposed)    View
43002  CVE-2010-0418  Candidate  The web interface in chumby one before 1.0.4 and chumby classic before 1.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a request.  Assigned (20100127)  None (candidate not yet proposed)    View
43258  CVE-2010-0674  Candidate  StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for path/stats.mdb.  Assigned (20100222)  None (candidate not yet proposed)    View
43514  CVE-2010-0930  Candidate  The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (infinite loop) via crafted data that includes a byte sequence of 0xdc, 0xff, 0xff, and 0xff immediately before the client protocol version number.  Assigned (20100305)  None (candidate not yet proposed)    View
43770  CVE-2010-1186  Candidate  Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter.  Assigned (20100330)  None (candidate not yet proposed)    View

Page 20525 of 20943, showing 5 records out of 104715 total, starting on record 102621, ending on 102625

Actions