CVE List

Id CVE No. Status Description Phase Votes Comments Actions
61713  CVE-2013-1766  Candidate  libvirt 1.0.2 and earlier sets the group owner to kvm for device files, which allows local users to write to these files via unspecified vectors.  Assigned (20130219)  None (candidate not yet proposed)    View
61969  CVE-2013-2022  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in actionscript/Jplayer.as in the Flash SWF component (jplayer.swf) in jPlayer before 2.2.23 allow remote attackers to inject arbitrary web script or HTML via the (1) jQuery or (2) id parameters, a different vulnerability than CVE-2013-1942 and CVE-2013-2023, as demonstrated by using the alert function in the jQuery parameter. NOTE: these are the same parameters as CVE-2013-1942, but the fix for CVE-2013-1942 uses a blacklist for the jQuery parameter.  Assigned (20130219)  None (candidate not yet proposed)    View
62225  CVE-2013-2278  Candidate  Unspecified vulnerability in War FTP Daemon (warftpd) 1.82, when running as a Windows service, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to log messages and the "internal log handler to the Windows Event log."  Assigned (20130226)  None (candidate not yet proposed)    View
62481  CVE-2013-2534  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130308)  None (candidate not yet proposed)    View
62737  CVE-2013-2790  Candidate  The master-station DNP3 driver before driver19.exe, and Beta2041.exe, in IOServer allows remote attackers to cause a denial of service (infinite loop) via crafted DNP3 packets to TCP port 20000.  Assigned (20130411)  None (candidate not yet proposed)    View

Page 1448 of 20943, showing 5 records out of 104715 total, starting on record 7236, ending on 7240

Actions