CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41732 | CVE-2009-4297 | Candidate | Multiple cross-site request forgery (CSRF) vulnerabilities in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors. | Assigned (20091211) | None (candidate not yet proposed) | View | |
41988 | CVE-2009-4553 | Candidate | Stack-based buffer overflow in iRehearse allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in a .m3u playlist file. | Assigned (20100104) | None (candidate not yet proposed) | View | |
42244 | CVE-2009-4809 | Candidate | Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to read arbitrary files via a .. (dot dot) in the vfolder parameter. | Assigned (20100423) | None (candidate not yet proposed) | View | |
42500 | CVE-2009-5065 | Candidate | Cross-site scripting (XSS) vulnerability in feedparser.py in Universal Feed Parser (aka feedparser or python-feedparser) before 5.0 allows remote attackers to inject arbitrary web script or HTML via vectors involving nested CDATA stanzas. | Assigned (20110405) | None (candidate not yet proposed) | View | |
42756 | CVE-2010-0172 | Candidate | toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances. | Assigned (20100106) | None (candidate not yet proposed) | View |
Page 386 of 20943, showing 5 records out of 104715 total, starting on record 1926, ending on 1930