CVE List

Id CVE No. Status Description Phase Votes Comments Actions
64021  CVE-2013-4074  Candidate  The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.  Assigned (20130609)  None (candidate not yet proposed)    View
64277  CVE-2013-4330  Candidate  Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.  Assigned (20130612)  None (candidate not yet proposed)    View
64533  CVE-2013-4586  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130612)  None (candidate not yet proposed)    View
64789  CVE-2013-4842  Candidate  Cross-site scripting (XSS) vulnerability in HP Integrated Lights-Out 4 (iLO4) with firmware before 1.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20130712)  None (candidate not yet proposed)    View
65045  CVE-2013-5098  Candidate  Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort parameter, a different vulnerability than CVE-2013-3262.  Assigned (20130809)  None (candidate not yet proposed)    View

Page 1749 of 20943, showing 5 records out of 104715 total, starting on record 8741, ending on 8745

Actions