CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40887 | CVE-2009-3452 | Candidate | WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname. | Assigned (20090929) | None (candidate not yet proposed) | View | |
43245 | CVE-2010-0661 | Candidate | WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method. | Assigned (20100218) | None (candidate not yet proposed) | View | |
31122 | CVE-2008-1005 | Candidate | WebCore, as used in Apple Safari before 3.1, does not properly mask the password field when reverse conversion is used with the Kotoeri input method, which allows physically proximate attackers to read the password. | Assigned (20080226) | None (candidate not yet proposed) | View | |
31124 | CVE-2008-1007 | Candidate | WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks. | Assigned (20080226) | None (candidate not yet proposed) | View | |
23835 | CVE-2007-0478 | Candidate | WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment. | Assigned (20070124) | None (candidate not yet proposed) | View |
Page 385 of 20943, showing 5 records out of 104715 total, starting on record 1921, ending on 1925