CVE List

Id CVE No. Status Description Phase Votes Comments Actions
64016  CVE-2013-4069  Candidate  The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.  Assigned (20130607)  None (candidate not yet proposed)    View
64272  CVE-2013-4325  Candidate  The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.  Assigned (20130612)  None (candidate not yet proposed)    View
64528  CVE-2013-4581  Candidate  GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.  Assigned (20130612)  None (candidate not yet proposed)    View
64784  CVE-2013-4837  Candidate  Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.  Assigned (20130712)  None (candidate not yet proposed)    View
65040  CVE-2013-5093  Candidate  The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.  Assigned (20130808)  None (candidate not yet proposed)    View

Page 1352 of 20943, showing 5 records out of 104715 total, starting on record 6756, ending on 6760

Actions