CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
59669 | CVE-2012-6426 | Candidate | LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data. | Assigned (20121218) | None (candidate not yet proposed) | View | |
59925 | CVE-2012-6682 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20141120) | None (candidate not yet proposed) | View | |
60181 | CVE-2013-0234 | Candidate | Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_username] parameter to action/widgets/save. | Assigned (20121206) | None (candidate not yet proposed) | View | |
60437 | CVE-2013-0490 | Candidate | Unspecified vulnerability in IBM InfoSphere Guardium S-TAP 8.1 for DB2 on z/OS allows local users to gain privileges via unknown vectors. | Assigned (20121216) | None (candidate not yet proposed) | View | |
60693 | CVE-2013-0746 | Candidate | Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 do not properly implement quickstubs that use the jsval data type for their return values, which allows remote attackers to execute arbitrary code or cause a denial of service (compartment mismatch and application crash) via crafted JavaScript code that is not properly handled during garbage collection. | Assigned (20130102) | None (candidate not yet proposed) | View |
Page 1727 of 20943, showing 5 records out of 104715 total, starting on record 8631, ending on 8635