CVE List

Id CVE No. Status Description Phase Votes Comments Actions
59670  CVE-2012-6427  Candidate  Multiple SQL injection vulnerabilities in Carlo Gavazzi EOS-Box with firmware before 1.0.0.1080_2.1.10 allow remote attackers to execute arbitrary SQL commands via unspecified vectors, a similar issue to CVE-2012-5861.  Assigned (20121218)  None (candidate not yet proposed)    View
59926  CVE-2012-6683  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141120)  None (candidate not yet proposed)    View
60182  CVE-2013-0235  Candidate  The XMLRPC API in WordPress before 3.5.1 allows remote attackers to send HTTP requests to intranet servers, and conduct port-scanning attacks, by specifying a crafted source URL for a pingback, related to a Server-Side Request Forgery (SSRF) issue.  Assigned (20121206)  None (candidate not yet proposed)    View
60438  CVE-2013-0491  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20121216)  None (candidate not yet proposed)    View
60694  CVE-2013-0747  Candidate  The gPluginHandler.handleEvent function in the plugin handler in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not properly enforce the Same Origin Policy, which allows remote attackers to conduct clickjacking attacks via crafted JavaScript code that listens for a mutation event.  Assigned (20130102)  None (candidate not yet proposed)    View

Page 1804 of 20943, showing 5 records out of 104715 total, starting on record 9016, ending on 9020

Actions