CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
59671 | CVE-2012-6428 | Candidate | Carlo Gavazzi EOS-Box with firmware before 1.0.0.1080_2.1.10 establishes multiple hardcoded accounts, which makes it easier for remote attackers to obtain administrative access by reading a password in a PHP script, a similar issue to CVE-2012-5862. | Assigned (20121218) | None (candidate not yet proposed) | View | |
59927 | CVE-2012-6684 | Candidate | Cross-site scripting (XSS) vulnerability in the RedCloth library 4.2.9 for Ruby and earlier allows remote attackers to inject arbitrary web script or HTML via a javascript: URI. | Assigned (20150105) | None (candidate not yet proposed) | View | |
60183 | CVE-2013-0236 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.1 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) gallery shortcodes or (2) the content of a post. | Assigned (20121206) | None (candidate not yet proposed) | View | |
60439 | CVE-2013-0492 | Candidate | Cross-site scripting (XSS) vulnerability in IBM Informix Open Admin Tool (OAT) 2.x and 3.x before 3.11.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL. | Assigned (20121216) | None (candidate not yet proposed) | View | |
60695 | CVE-2013-0748 | Candidate | The XBL.__proto__.toString implementation in Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before 10.0.12 and 17.x before 17.0.2, and SeaMonkey before 2.15 makes it easier for remote attackers to bypass the ASLR protection mechanism by calling the toString function of an XBL object. | Assigned (20130102) | None (candidate not yet proposed) | View |
Page 1881 of 20943, showing 5 records out of 104715 total, starting on record 9401, ending on 9405