CVE List

Id CVE No. Status Description Phase Votes Comments Actions
62435  CVE-2013-2488  Candidate  The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location.  Assigned (20130306)  None (candidate not yet proposed)    View
62691  CVE-2013-2744  Candidate  importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.  Assigned (20130401)  None (candidate not yet proposed)    View
62947  CVE-2013-3000  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130412)  None (candidate not yet proposed)    View
63203  CVE-2013-3256  Candidate  Cross-site request forgery (CSRF) vulnerability in the Shareaholic SexyBookmarks plugin 6.1.4.0 for WordPress allows remote attackers to hijack the authentication of users for requests that "manipulate plugin settings."  Assigned (20130422)  None (candidate not yet proposed)    View
63459  CVE-2013-3512  Candidate  The Cacti component in GroundWork Monitor Enterprise 6.7.0 does not properly perform authorization checks, which allows remote authenticated users to read or modify configuration settings via unspecified vectors, as demonstrated by reading credentials.  Assigned (20130508)  None (candidate not yet proposed)    View

Page 18696 of 20943, showing 5 records out of 104715 total, starting on record 93476, ending on 93480

Actions