CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25767  CVE-2007-2410  Candidate  WebCore on Apple Mac OS X 10.3.9 and 10.4.10 retains properties of certain global objects when a new URL is visited in the same window, which allows remote attackers to conduct cross-site scripting (XSS) attacks.  Assigned (20070430)  None (candidate not yet proposed)    View
23699  CVE-2007-0342  Candidate  WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPAN attribute, as demonstrated by a crash of OmniWeb 5.5.3 on Mac OS X 10.4.8, a different vulnerability than CVE-2006-2019.  Assigned (20070117)  None (candidate not yet proposed)    View
32434  CVE-2008-2317  Candidate  WebCore in Apple Safari does not properly perform garbage collection of JavaScript document elements, which allows remote attackers to execute arbitrary code or cause a denial of service (heap corruption and application crash) via a reference to the ownerNode property of a copied CSSStyleSheet object of a STYLE element, as originally demonstrated on Apple iPhone before 2.0 and iPod touch before 2.0, a different vulnerability than CVE-2008-1590.  Assigned (20080518)  None (candidate not yet proposed)    View
20050  CVE-2006-3946  Candidate  WebCore in Apple Mac OS X 10.3.9 and 10.4 through 10.4.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted HTML that triggers a "memory management error" in WebKit, possibly due to a buffer overflow, as originally reported for the KHTMLParser::popOneBlock function in Apple Safari 2.0.4 using Javascript that changes document.body.innerHTML within a DIV tag.  Assigned (20060731)  None (candidate not yet proposed)    View
31807  CVE-2008-1690  Candidate  WebContainer.exe 1.0.0.336 and earlier in SLMail Pro 6.3.1.0 and earlier allows remote attackers to cause a denial of service (memory corruption and daemon crash) or possibly execute arbitrary code via a long URI in HTTP requests to TCP port 801. NOTE: some of these details are obtained from third party information.  Assigned (20080407)  None (candidate not yet proposed)    View

Page 386 of 20943, showing 5 records out of 104715 total, starting on record 1926, ending on 1930

Actions