CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40451  CVE-2009-3016  Candidate  Apple Safari 4.0.3 does not properly block javascript: and data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains a javascript: URI, (2) entering a javascript: URI when specifying the content of a Refresh header, (3) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI, or (4) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header.  Assigned (20090831)  None (candidate not yet proposed)    View
40707  CVE-2009-3272  Candidate  Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2, allows remote attackers to cause a denial of service (application crash) via JavaScript code that calls eval on a long string composed of A/ sequences.  Assigned (20090921)  None (candidate not yet proposed)    View
40963  CVE-2009-3528  Candidate  SQL injection vulnerability in Profile.php in MyMsg 1.0.3 allows remote authenticated users to execute arbitrary SQL commands via the uid parameter in a show action.  Assigned (20091002)  None (candidate not yet proposed)    View
41219  CVE-2009-3784  Candidate  Open redirect vulnerability in Simplenews Statistics 6.x before 6.x-2.0, a module for Drupal, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.  Assigned (20091026)  None (candidate not yet proposed)    View
41475  CVE-2009-4040  Candidate  Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page.  Assigned (20091120)  None (candidate not yet proposed)    View

Page 911 of 20943, showing 5 records out of 104715 total, starting on record 4551, ending on 4555

Actions