CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40700  CVE-2009-3265  Candidate  Cross-site scripting (XSS) vulnerability in Opera 9 and 10 allows remote attackers to inject arbitrary web script or HTML via a (1) RSS or (2) Atom feed, related to the rendering of the application/rss+xml content type as "scripted content." NOTE: the vendor reportedly considers this behavior a "design feature," not a vulnerability.  Assigned (20090918)  None (candidate not yet proposed)    View
40956  CVE-2009-3521  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the Visualization Engine (VE) in IBM Tivoli Composite Application Manager for WebSphere (ITCAM) 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20091001)  None (candidate not yet proposed)    View
41212  CVE-2009-3777  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20091023)  None (candidate not yet proposed)    View
41468  CVE-2009-4033  Candidate  A certain Red Hat patch for acpid 1.0.4 effectively triggers a call to the open function with insufficient arguments, which might allow local users to leverage weak permissions on /var/log/acpid, and obtain sensitive information by reading this file, cause a denial of service by overwriting this file, or gain privileges by executing this file.  Assigned (20091120)  None (candidate not yet proposed)    View
41724  CVE-2009-4289  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20091210)  None (candidate not yet proposed)    View

Page 20686 of 20943, showing 5 records out of 104715 total, starting on record 103426, ending on 103430

Actions