CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40191 | CVE-2009-2756 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20090812) | None (candidate not yet proposed) | View | |
40447 | CVE-2009-3012 | Candidate | Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header. NOTE: the JavaScript executes outside of the context of the HTTP site. | Assigned (20090831) | None (candidate not yet proposed) | View | |
40703 | CVE-2009-3268 | Candidate | Google Chrome 1.0.154.48 and earlier allows remote attackers to cause a denial of service (CPU consumption) via an automatically submitted form containing a KEYGEN element, a related issue to CVE-2009-1828. | Assigned (20090918) | None (candidate not yet proposed) | View | |
40959 | CVE-2009-3524 | Candidate | Unspecified vulnerability in ashWsFtr.dll in avast! Home and Professional for Windows before 4.8.1356 has unknown impact and local attack vectors. | Assigned (20091001) | None (candidate not yet proposed) | View | |
41215 | CVE-2009-3780 | Candidate | Cross-site scripting (XSS) vulnerability in Abuse 5.x before 5.x-2.1 and 6.x before 6.x-1.1-alpha1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20091026) | None (candidate not yet proposed) | View |
Page 20924 of 20943, showing 5 records out of 104715 total, starting on record 104616, ending on 104620