CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40443  CVE-2009-3008  Candidate  K-Meleon 1.5.3 allows context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.  Assigned (20090828)  None (candidate not yet proposed)    View
40699  CVE-2009-3264  Candidate  The getSVGDocument method in Google Chrome before 3.0.195.21 omits an unspecified "access check," which allows remote web servers to bypass the Same Origin Policy and conduct cross-site scripting attacks via unknown vectors, related to a user"s visit to a different web server that hosts an SVG document.  Assigned (20090918)  None (candidate not yet proposed)    View
40955  CVE-2009-3520  Candidate  Cross-site request forgery (CSRF) vulnerability in the Your_account module in CMSphp 0.21 allows remote attackers to hijack the authentication of administrators for requests that change an administrator password via the pseudo, pwd, and uid parameters in an admin_info_user_verif action.  Assigned (20091001)  None (candidate not yet proposed)    View
41211  CVE-2009-3776  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20091023)  None (candidate not yet proposed)    View
41467  CVE-2009-4032  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.7e allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) graph.php, (2) include/top_graph_header.php, (3) lib/html_form.php, and (4) lib/timespan_settings.php, as demonstrated by the (a) graph_end or (b) graph_start parameters to graph.php; (c) the date1 parameter in a tree action to graph_view.php; and the (d) page_refresh and (e) default_dual_pane_width parameters to graph_settings.php.  Assigned (20091120)  None (candidate not yet proposed)    View

Page 20606 of 20943, showing 5 records out of 104715 total, starting on record 103026, ending on 103030

Actions