CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40195  CVE-2009-2760  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20090812)  None (candidate not yet proposed)    View
40451  CVE-2009-3016  Candidate  Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header.  Assigned (20090831)  None (candidate not yet proposed)    View
40707  CVE-2009-3272  Candidate  Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls eval on a long string composed of A/ sequences.  Assigned (20090921)  None (candidate not yet proposed)    View
40963  CVE-2009-3528  Candidate  SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action.  Assigned (20091002)  None (candidate not yet proposed)    View
41219  CVE-2009-3784  Candidate  Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.  Assigned (20091026)  None (candidate not yet proposed)    View

Page 327 of 20943, showing 5 records out of 104715 total, starting on record 1631, ending on 1635

Actions