CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
63203 | CVE-2013-3256 | Candidate | Cross-site request forgery (CSRF) vulnerability in the Shareaholic SexyBookmarks plugin 6.1.4.0 for WordPress allows remote attackers to hijack the authentication of users for requests that "manipulate plugin settings." | Assigned (20130422) | None (candidate not yet proposed) | View | |
63459 | CVE-2013-3512 | Candidate | The Cacti component in GroundWork Monitor Enterprise 6.7.0 does not properly perform authorization checks, which allows remote authenticated users to read or modify configuration settings via unspecified vectors, as demonstrated by reading credentials. | Assigned (20130508) | None (candidate not yet proposed) | View | |
63715 | CVE-2013-3768 | Candidate | Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect integrity via unknown vectors related to Rich Text Editor. | Assigned (20130603) | None (candidate not yet proposed) | View | |
63971 | CVE-2013-4024 | Candidate | IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network. | Assigned (20130607) | None (candidate not yet proposed) | View | |
64227 | CVE-2013-4280 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20130612) | None (candidate not yet proposed) | View |
Page 18746 of 20943, showing 5 records out of 104715 total, starting on record 93726, ending on 93730