CVE List

Id CVE No. Status Description Phase Votes Comments Actions
59669  CVE-2012-6426  Candidate  LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.  Assigned (20121218)  None (candidate not yet proposed)    View
59925  CVE-2012-6682  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141120)  None (candidate not yet proposed)    View
60181  CVE-2013-0234  Candidate  Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_username] parameter to action/widgets/save.  Assigned (20121206)  None (candidate not yet proposed)    View
60437  CVE-2013-0490  Candidate  Unspecified vulnerability in IBM InfoSphere Guardium S-TAP 8.1 for DB2 on z/OS allows local users to gain privileges via unknown vectors.  Assigned (20121216)  None (candidate not yet proposed)    View
60693  CVE-2013-0746  Candidate  Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 do not properly implement quickstubs that use the jsval data type for their return values, which allows remote attackers to execute arbitrary code or cause a denial of service (compartment mismatch and application crash) via crafted JavaScript code that is not properly handled during garbage collection.  Assigned (20130102)  None (candidate not yet proposed)    View

Page 1727 of 20943, showing 5 records out of 104715 total, starting on record 8631, ending on 8635

Actions