CVE List

Id CVE No. Status Description Phase Votes Comments Actions
59671  CVE-2012-6428  Candidate  Carlo Gavazzi EOS-Box with firmware before 1.0.0.1080_2.1.10 establishes multiple hardcoded accounts, which makes it easier for remote attackers to obtain administrative access by reading a password in a PHP script, a similar issue to CVE-2012-5862.  Assigned (20121218)  None (candidate not yet proposed)    View
59927  CVE-2012-6684  Candidate  Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI.  Assigned (20150105)  None (candidate not yet proposed)    View
60183  CVE-2013-0236  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post.  Assigned (20121206)  None (candidate not yet proposed)    View
60439  CVE-2013-0492  Candidate  Cross-site scripting (XSS) vulnerability in IBM Informix Open Admin Tool (OAT) 2.x and 3.x before 3.11.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.  Assigned (20121216)  None (candidate not yet proposed)    View
60695  CVE-2013-0748  Candidate  The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 makes it easier for remote attackers to bypass the ASLR protection mechanism by calling the toString function of an XBL object.  Assigned (20130102)  None (candidate not yet proposed)    View

Page 1881 of 20943, showing 5 records out of 104715 total, starting on record 9401, ending on 9405

Actions