CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
44391 | CVE-2010-1807 | Candidate | WebKit in Apple Safari 4.x before 4.1.2 and 5.x before 5.0.2; Android before 2.2; and webkitgtk before 1.2.6; does not properly validate floating-point data, which allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted HTML document, related to non-standard NaN representation. | Assigned (20100506) | None (candidate not yet proposed) | View | |
39145 | CVE-2009-1710 | Candidate | WebKit in Apple Safari before 4.0 allows remote attackers to spoof the browser"s display of (1) the host name, (2) security indicators, and unspecified other UI elements via a custom cursor in conjunction with a modified CSS3 hotspot property. | Assigned (20090520) | None (candidate not yet proposed) | View | |
39153 | CVE-2009-1718 | Candidate | WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dragging of content over a crafted web page. | Assigned (20090520) | None (candidate not yet proposed) | View | |
39138 | CVE-2009-1703 | Candidate | WebKit in Apple Safari before 4.0 does not prevent references to file: URLs within (1) audio and (2) video elements, which allows remote attackers to determine the existence of arbitrary files via a crafted HTML document. | Assigned (20090520) | None (candidate not yet proposed) | View | |
39147 | CVE-2009-1712 | Candidate | WebKit in Apple Safari before 4.0 does not prevent remote loading of local Java applets, which allows remote attackers to execute arbitrary code, gain privileges, or obtain sensitive information via an APPLET or OBJECT element. | Assigned (20090520) | None (candidate not yet proposed) | View |
Page 20579 of 20943, showing 5 records out of 104715 total, starting on record 102891, ending on 102895