CVE List

Id CVE No. Status Description Phase Votes Comments Actions
44808  CVE-2010-2224  Candidate  The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted volumes, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.  Assigned (20100609)  None (candidate not yet proposed)    View
45064  CVE-2010-2480  Candidate  Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.  Assigned (20100628)  None (candidate not yet proposed)    View
45320  CVE-2010-2736  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20100714)  None (candidate not yet proposed)    View
45576  CVE-2010-2992  Candidate  packet-gsm_a_rr.c in the GSM A RR dissector in Wireshark 1.2.2 through 1.2.9 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger a NULL pointer dereference.  Assigned (20100811)  None (candidate not yet proposed)    View
45832  CVE-2010-3248  Candidate  Google Chrome before 6.0.472.53 does not properly restrict copying to the clipboard, which has unspecified impact and attack vectors.  Assigned (20100907)  None (candidate not yet proposed)    View

Page 704 of 20943, showing 5 records out of 104715 total, starting on record 3516, ending on 3520

Actions