CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63203  CVE-2013-3256  Candidate  Cross-site request forgery (CSRF) vulnerability in the Shareaholic SexyBookmarks plugin 6.1.4.0 for WordPress allows remote attackers to hijack the authentication of users for requests that "manipulate plugin settings."  Assigned (20130422)  None (candidate not yet proposed)    View
63459  CVE-2013-3512  Candidate  The Cacti component in GroundWork Monitor Enterprise 6.7.0 does not properly perform authorization checks, which allows remote authenticated users to read or modify configuration settings via unspecified vectors, as demonstrated by reading credentials.  Assigned (20130508)  None (candidate not yet proposed)    View
63715  CVE-2013-3768  Candidate  Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via unknown vectors related to Rich Text Editor.  Assigned (20130603)  None (candidate not yet proposed)    View
63971  CVE-2013-4024  Candidate  IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.  Assigned (20130607)  None (candidate not yet proposed)    View
64227  CVE-2013-4280  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130612)  None (candidate not yet proposed)    View

Page 18746 of 20943, showing 5 records out of 104715 total, starting on record 93726, ending on 93730

Actions