CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40187 | CVE-2009-2752 | Candidate | IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms. | Assigned (20090812) | None (candidate not yet proposed) | View | |
40443 | CVE-2009-3008 | Candidate | K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker. | Assigned (20090828) | None (candidate not yet proposed) | View | |
40699 | CVE-2009-3264 | Candidate | The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user"s visit to a different web server that hosts an SVG document. | Assigned (20090918) | None (candidate not yet proposed) | View | |
40955 | CVE-2009-3520 | Candidate | Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of administrators for requests that change an administrator password via the pseudo, pwd, and uid parameters in an admin_info_user_verif action. | Assigned (20091001) | None (candidate not yet proposed) | View | |
41211 | CVE-2009-3776 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20091023) | None (candidate not yet proposed) | View |
Page 20603 of 20943, showing 5 records out of 104715 total, starting on record 103011, ending on 103015