Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2010-4209
Description:Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.8.0 through 2.8.1, as used in Bugzilla 3.7.1 through 3.7.3 and 4.1, allows remote attackers to inject arbitrary web script or HTML via vectors related to swfstore/swfstore.swf.
Test IDs: 1.3.6.1.4.1.25623.1.0.68592   1.3.6.1.4.1.25623.1.0.68593   1.3.6.1.4.1.25623.1.0.68591   1.3.6.1.4.1.25623.1.0.68688  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2010-4209
BugTraq ID: 44420
http://www.securityfocus.com/bid/44420
Bugtraq: 20101103 Security Advisory for Bugzilla 3.2.8, 3.4.8, 3.6.2, and 3.7.3 (Google Search)
http://www.securityfocus.com/archive/1/514622
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050830.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050820.html
http://lists.fedoraproject.org/pipermail/package-announce/2010-November/050813.html
http://www.openwall.com/lists/oss-security/2010/11/07/1
http://www.securitytracker.com/id?1024683
http://secunia.com/advisories/41955
http://secunia.com/advisories/42271
SuSE Security Announcement: SUSE-SR:2010:021 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2010-11/msg00005.html
http://www.vupen.com/english/advisories/2010/2878
http://www.vupen.com/english/advisories/2010/2975




© 1998-2025 E-Soft Inc. All rights reserved.