CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
42755 | CVE-2010-0171 | Candidate | Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736. | Assigned (20100106) | None (candidate not yet proposed) | View | |
43011 | CVE-2010-0427 | Candidate | sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command. | Assigned (20100127) | None (candidate not yet proposed) | View | |
43267 | CVE-2010-0683 | Candidate | Unspecified vulnerability in TIBRepoServer5.jar in TIBCO Administrator 5.4.0 through 5.6.0, when JMS transport is used, allows remote authenticated users to execute arbitrary code on all domain nodes via vectors related to leveraging administrative credentials. | Assigned (20100222) | None (candidate not yet proposed) | View | |
43523 | CVE-2010-0939 | Candidate | Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for fpdb/abb.mdb. | Assigned (20100308) | None (candidate not yet proposed) | View | |
43779 | CVE-2010-1195 | Candidate | Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI. | Assigned (20100330) | None (candidate not yet proposed) | View |
Page 329 of 20943, showing 5 records out of 104715 total, starting on record 1641, ending on 1645