CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41732  CVE-2009-4297  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.  Assigned (20091211)  None (candidate not yet proposed)    View
41988  CVE-2009-4553  Candidate  Stack-based buffer overflow in iRehearse allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in a .m3u playlist file.  Assigned (20100104)  None (candidate not yet proposed)    View
42244  CVE-2009-4809  Candidate  Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the vfolder parameter.  Assigned (20100423)  None (candidate not yet proposed)    View
42500  CVE-2009-5065  Candidate  Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas.  Assigned (20110405)  None (candidate not yet proposed)    View
42756  CVE-2010-0172  Candidate  toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.  Assigned (20100106)  None (candidate not yet proposed)    View

Page 386 of 20943, showing 5 records out of 104715 total, starting on record 1926, ending on 1930

Actions