CVE List

Id CVE No. Status Description Phase Votes Comments Actions
44552  CVE-2010-1968  Candidate  Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1971.  Assigned (20100519)  None (candidate not yet proposed)    View
44808  CVE-2010-2224  Candidate  The snapshot merging functionality in Red Hat Enterprise Virtualization Manager (aka RHEV-M) before 2.2 does not properly pass the postzero parameter during operations on deleted volumes, which allows guest OS users to obtain sensitive information by examining the disk blocks associated with a deleted virtual machine.  Assigned (20100609)  None (candidate not yet proposed)    View
45064  CVE-2010-2480  Candidate  Mako before 0.3.4 relies on the cgi.escape function in the Python standard library for cross-site scripting (XSS) protection, which makes it easier for remote attackers to conduct XSS attacks via vectors involving single-quote characters and a JavaScript onLoad event handler for a BODY element.  Assigned (20100628)  None (candidate not yet proposed)    View
45320  CVE-2010-2736  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20100714)  None (candidate not yet proposed)    View
45576  CVE-2010-2992  Candidate  packet-gsm_a_rr.c in the GSM A RR dissector in Wireshark 1.2.2 through 1.2.9 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigger a NULL pointer dereference.  Assigned (20100811)  None (candidate not yet proposed)    View

Page 716 of 20943, showing 5 records out of 104715 total, starting on record 3576, ending on 3580

Actions