CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43531  CVE-2010-0947  Candidate  Cross-site scripting (XSS) vulnerability in post.aspx in Max Network Technology BBSMAX 3.0, 4.1, and 4.2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.  Assigned (20100309)  None (candidate not yet proposed)    View
43787  CVE-2010-1203  Candidate  The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.  Assigned (20100330)  None (candidate not yet proposed)    View
44043  CVE-2010-1459  Candidate  The default configuration of ASP.NET in Mono before 2.6.4 has a value of FALSE for the EnableViewStateMac property, which allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by the __VIEWSTATE parameter to 2.0/menu/menu1.aspx in the XSP sample project.  Assigned (20100416)  None (candidate not yet proposed)    View
44299  CVE-2010-1715  Candidate  Directory traversal vulnerability in the Online Examination (aka Online Exam or com_onlineexam) component 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information.  Assigned (20100504)  None (candidate not yet proposed)    View
44555  CVE-2010-1971  Candidate  Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1968.  Assigned (20100519)  None (candidate not yet proposed)    View

Page 951 of 20943, showing 5 records out of 104715 total, starting on record 4751, ending on 4755

Actions