CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40887  CVE-2009-3452  Candidate  WebCoreModule.ashx in RADactive I-Load before 2008.2.5.0 allows remote attackers to obtain sensitive information via unspecified requests that trigger responses containing the saved-image folder pathname.  Assigned (20090929)  None (candidate not yet proposed)    View
43245  CVE-2010-0661  Candidate  WebCore/bindings/v8/custom/V8DOMWindowCustom.cpp in WebKit before r52401, as used in Google Chrome before 4.0.249.78, allows remote attackers to bypass the Same Origin Policy via vectors involving the window.open method.  Assigned (20100218)  None (candidate not yet proposed)    View
31122  CVE-2008-1005  Candidate  WebCore, as used in Apple Safari before 3.1, does not properly mask the password field when reverse conversion is used with the Kotoeri input method, which allows physically proximate attackers to read the password.  Assigned (20080226)  None (candidate not yet proposed)    View
31124  CVE-2008-1007  Candidate  WebCore, as used in Apple Safari before 3.1, does not enforce the frame navigation policy for Java applets, which allows remote attackers to conduct cross-site scripting (XSS) attacks.  Assigned (20080226)  None (candidate not yet proposed)    View
23835  CVE-2007-0478  Candidate  WebCore on Apple Mac OS X 10.3.9 and 10.4.10, as used in Safari, does not properly parse HTML comments in TITLE elements, which allows remote attackers to conduct cross-site scripting (XSS) attacks and bypass some XSS protection schemes by embedding certain HTML tags within an HTML comment.  Assigned (20070124)  None (candidate not yet proposed)    View

Page 385 of 20943, showing 5 records out of 104715 total, starting on record 1921, ending on 1925

Actions