CVE List

Id CVE No. Status Description Phase Votes Comments Actions
59878  CVE-2012-6635  Candidate  wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.  Assigned (20140120)  None (candidate not yet proposed)    View
60134  CVE-2013-0187  Candidate  Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.  Assigned (20121206)  None (candidate not yet proposed)    View
60390  CVE-2013-0443  Candidate  Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality and integrity via vectors related to JSSE. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to incorrect validation of Diffie-Hellman keys, which allows remote attackers to conduct a "small subgroup attack" to force the use of weak session keys or obtain sensitive information about the private key.  Assigned (20121207)  None (candidate not yet proposed)    View
60646  CVE-2013-0699  Candidate  The Galil RIO-47100 Pocket PLC allows remote attackers to cause a denial of service via a session that includes "repeated requests."  Assigned (20121219)  None (candidate not yet proposed)    View
60902  CVE-2013-0955  Candidate  WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.  Assigned (20130110)  None (candidate not yet proposed)    View

Page 18935 of 20943, showing 5 records out of 104715 total, starting on record 94671, ending on 94675

Actions