CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42755  CVE-2010-0171  Candidate  Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736.  Assigned (20100106)  None (candidate not yet proposed)    View
43011  CVE-2010-0427  Candidate  sudo 1.6.x before 1.6.9p21, when the runas_default option is used, does not properly set group memberships, which allows local users to gain privileges via a sudo command.  Assigned (20100127)  None (candidate not yet proposed)    View
43267  CVE-2010-0683  Candidate  Unspecified vulnerability in TIBRepoServer5.jar in TIBCO Administrator 5.4.0 through 5.6.0, when JMS transport is used, allows remote authenticated users to execute arbitrary code on all domain nodes via vectors related to leveraging administrative credentials.  Assigned (20100222)  None (candidate not yet proposed)    View
43523  CVE-2010-0939  Candidate  Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for fpdb/abb.mdb.  Assigned (20100308)  None (candidate not yet proposed)    View
43779  CVE-2010-1195  Candidate  Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI.  Assigned (20100330)  None (candidate not yet proposed)    View

Page 329 of 20943, showing 5 records out of 104715 total, starting on record 1641, ending on 1645

Actions