CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40187  CVE-2009-2752  Candidate  IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.  Assigned (20090812)  None (candidate not yet proposed)    View
40443  CVE-2009-3008  Candidate  K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.  Assigned (20090828)  None (candidate not yet proposed)    View
40699  CVE-2009-3264  Candidate  The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user"s visit to a different web server that hosts an SVG document.  Assigned (20090918)  None (candidate not yet proposed)    View
40955  CVE-2009-3520  Candidate  Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of administrators for requests that change an administrator password via the pseudo, pwd, and uid parameters in an admin_info_user_verif action.  Assigned (20091001)  None (candidate not yet proposed)    View
41211  CVE-2009-3776  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20091023)  None (candidate not yet proposed)    View

Page 20603 of 20943, showing 5 records out of 104715 total, starting on record 103011, ending on 103015

Actions