CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40448 | CVE-2009-3013 | Candidate | Opera 9.52 and earlier, and 10.00 Beta 3 Build 1699, does not properly block data: URIs in Location headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Location header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Location header. NOTE: the JavaScript executes outside of the context of the HTTP site. | Assigned (20090831) | None (candidate not yet proposed) | View | |
40704 | CVE-2009-3269 | Candidate | Opera 9.52 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a series of automatic submissions of a form containing a KEYGEN element, a related issue to CVE-2009-1828. | Assigned (20090918) | None (candidate not yet proposed) | View | |
40960 | CVE-2009-3525 | Candidate | The pyGrub boot loader in Xen 3.0.3, 3.3.0, and Xen-3.3.1 does not support the password option in grub.conf for para-virtualized guests, which allows attackers with access to the para-virtualized guest console to boot the guest or modify the guest"s kernel boot parameters without providing the expected password. | Assigned (20091001) | None (candidate not yet proposed) | View | |
41216 | CVE-2009-3781 | Candidate | The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors. | Assigned (20091026) | None (candidate not yet proposed) | View | |
41472 | CVE-2009-4037 | Candidate | Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7, and 2.2.x before 2.2 RC, allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) admin/db/users_db.inc, and various other .inc and .php files under (2) admin/, (3) dimensions/, (4) gl/, (5) inventory/, (6) manufacturing/, and (7) purchasing/. | Assigned (20091120) | None (candidate not yet proposed) | View |
Page 62 of 20943, showing 5 records out of 104715 total, starting on record 306, ending on 310