CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
63247 | CVE-2013-3300 | Candidate | The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users" sessions via invalid input data containing a < (less than) character. | Assigned (20130426) | None (candidate not yet proposed) | View | |
63503 | CVE-2013-3556 | Candidate | The fragment_add_seq_common function in epan/reassemble.c in the ASN.1 BER dissector in Wireshark before r48943 has an incorrect pointer dereference during a comparison, which allows remote attackers to cause a denial of service (application crash) via a malformed packet. | Assigned (20130520) | None (candidate not yet proposed) | View | |
63759 | CVE-2013-3812 | Candidate | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Replication. | Assigned (20130603) | None (candidate not yet proposed) | View | |
64015 | CVE-2013-4068 | Candidate | Buffer overflow in iNotes in IBM Domino 8.5.3 before FP5 IF1 and 9.0 before IF4 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka SPR PTHN9ADPA8. | Assigned (20130607) | None (candidate not yet proposed) | View | |
64271 | CVE-2013-4324 | Candidate | spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288. | Assigned (20130612) | None (candidate not yet proposed) | View |
Page 1288 of 20943, showing 5 records out of 104715 total, starting on record 6436, ending on 6440