CVE List

Id CVE No. Status Description Phase Votes Comments Actions
62693  CVE-2013-2746  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130402)  None (candidate not yet proposed)    View
62949  CVE-2013-3002  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130412)  None (candidate not yet proposed)    View
63205  CVE-2013-3258  Candidate  Cross-site request forgery (CSRF) vulnerability in he Digg Digg plugin before 5.3.5 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings via unspecified vectors.  Assigned (20130422)  None (candidate not yet proposed)    View
63461  CVE-2013-3514  Candidate  Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a .. (dot dot) in the group parameter to (1) plugin-preferences.php or (2) plugin-settings.php in www/admin, a different vulnerability than CVE-2013-7376. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to read arbitrary files.  Assigned (20130508)  None (candidate not yet proposed)    View
63717  CVE-2013-3770  Candidate  Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1, 11.1.1.6.0, and 11.1.1.7.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Content Server. NOTE: the previous information is from the October 2013 CPU. Oracle has not commented on claims from a third party that the issue is related to "iDoc script injection" in the (1) cs and (2) urm components, which allows attackers to read "sensitive" files, as demonstrated by obtaining the "AES encryption key and encrypted credentials" of the weblogic user.  Assigned (20130603)  None (candidate not yet proposed)    View

Page 18900 of 20943, showing 5 records out of 104715 total, starting on record 94496, ending on 94500

Actions