CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
64016 | CVE-2013-4069 | Candidate | The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | Assigned (20130607) | None (candidate not yet proposed) | View | |
64272 | CVE-2013-4325 | Candidate | The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64528 | CVE-2013-4581 | Candidate | GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64784 | CVE-2013-4837 | Candidate | Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832. | Assigned (20130712) | None (candidate not yet proposed) | View | |
65040 | CVE-2013-5093 | Candidate | The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object. | Assigned (20130808) | None (candidate not yet proposed) | View |
Page 1352 of 20943, showing 5 records out of 104715 total, starting on record 6756, ending on 6760