CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63247  CVE-2013-3300  Candidate  The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users" sessions via invalid input data containing a < (less than) character.  Assigned (20130426)  None (candidate not yet proposed)    View
63503  CVE-2013-3556  Candidate  The fragment_add_seq_common function in epan/reassemble.c in the ASN.1 BER dissector in Wireshark before r48943 has an incorrect pointer dereference during a comparison, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.  Assigned (20130520)  None (candidate not yet proposed)    View
63759  CVE-2013-3812  Candidate  Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication.  Assigned (20130603)  None (candidate not yet proposed)    View
64015  CVE-2013-4068  Candidate  Buffer overflow in iNotes in IBM Domino 8.5.3 before FP5 IF1 and 9.0 before IF4 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka SPR PTHN9ADPA8.  Assigned (20130607)  None (candidate not yet proposed)    View
64271  CVE-2013-4324  Candidate  spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.  Assigned (20130612)  None (candidate not yet proposed)    View

Page 1288 of 20943, showing 5 records out of 104715 total, starting on record 6436, ending on 6440

Actions