CVE List

Id CVE No. Status Description Phase Votes Comments Actions
61159  CVE-2013-1212  Candidate  The SSL functionality in Cisco NX-OS on the Nexus 1000V does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof servers, and intercept or modify Virtual Supervisor Module (VSM) to VMware vCenter communication, via a crafted certificate, aka Bug ID CSCud14837.  Assigned (20130111)  None (candidate not yet proposed)    View
61415  CVE-2013-1468  Candidate  Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create arbitrary PHP files via unspecified vectors.  Assigned (20130129)  None (candidate not yet proposed)    View
61671  CVE-2013-1724  Candidate  Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving a destroyed SELECT element.  Assigned (20130213)  None (candidate not yet proposed)    View
61927  CVE-2013-1980  Candidate  Buffer overflow in the get_dsmp function in loaders/masi_load.c in libxmp before 4.1.0 allows remote attackers to execute arbitrary code via a crafted MASI file.  Assigned (20130219)  None (candidate not yet proposed)    View
62183  CVE-2013-2236  Candidate  Stack-based buffer overflow in the new_msg_lsa_change_notify function in the OSPFD API (ospf_api.c) in Quagga before 0.99.22.2, when --enable-opaque-lsa and the -a command line option are used, allows remote attackers to cause a denial of service (crash) via a large LSA.  Assigned (20130219)  None (candidate not yet proposed)    View

Page 19053 of 20943, showing 5 records out of 104715 total, starting on record 95261, ending on 95265

Actions