CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
48081 | CVE-2011-0169 | Candidate | WebKit in Apple Safari before 5.0.4, when the Web Inspector is used, does not properly handle the window.console._inspectorCommandLineAPI property, which allows user-assisted remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted web site. | Assigned (20101223) | None (candidate not yet proposed) | View | |
48156 | CVE-2011-0244 | Candidate | WebKit in Apple Safari before 5.0.6 allows user-assisted remote attackers to read arbitrary files via vectors related to improper canonicalization of URLs within RSS feeds. | Assigned (20101223) | None (candidate not yet proposed) | View | |
49686 | CVE-2011-1774 | Candidate | WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted web site. NOTE: this may overlap CVE-2011-1425. | Assigned (20110419) | None (candidate not yet proposed) | View | |
53890 | CVE-2012-0647 | Candidate | WebKit in Apple Safari before 5.1.4 does not properly handle redirects in conjunction with HTTP authentication, which might allow remote web servers to capture credentials by logging the Authorization HTTP header. | Assigned (20120112) | None (candidate not yet proposed) | View | |
53883 | CVE-2012-0640 | Candidate | WebKit in Apple Safari before 5.1.4 does not properly implement "From third parties and advertisers" cookie blocking, which makes it easier for remote web servers to track users via a cookie. | Assigned (20120112) | None (candidate not yet proposed) | View |
Page 20588 of 20943, showing 5 records out of 104715 total, starting on record 102936, ending on 102940