CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
62108 | CVE-2013-2161 | Candidate | XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name. | Assigned (20130219) | None (candidate not yet proposed) | View | |
36176 | CVE-2008-6059 | Candidate | xml/XMLHttpRequest.cpp in WebCore in WebKit before r38566 does not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism. | Assigned (20090204) | None (candidate not yet proposed) | View | |
35057 | CVE-2008-4940 | Candidate | xmlfile.py in aptoncd 0.1 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/aptoncd temporary file. | Assigned (20081105) | None (candidate not yet proposed) | View | |
4451 | CVE-2002-0057 | Entry | XMLHTTP control in Microsoft XML Core Services 2.6 and later does not properly handle IE Security Zone settings, which allows remote attackers to read arbitrary files by specifying a local file as an XML Data Source. | View | |||
86250 | CVE-2015-8973 | Candidate | xmlhttp.php in MyBB (aka MyBulletinBoard) before 1.6.18 and 1.8.x before 1.8.6 and MyBB Merge System before 1.8.6 allows remote attackers to bypass intended access restrictions via vectors related to the forum password. | Assigned (20161117) | None (candidate not yet proposed) | View |
Page 20875 of 20943, showing 5 records out of 104715 total, starting on record 104371, ending on 104375