CVE List

Id CVE No. Status Description Phase Votes Comments Actions
62440  CVE-2013-2493  Candidate  The Hook_Terminate function in chrome_frame/protocol_sink_wrap.cc in the Google Chrome Frame plugin before 26.0.1410.28 for Internet Explorer does not properly handle attach tab requests, which allows user-assisted remote attackers to cause a denial of service (application crash) via an _blank value for the target attribute of an A element.  Assigned (20130307)  None (candidate not yet proposed)    View
62696  CVE-2013-2749  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3528. Reason: This candidate is a reservation duplicate of CVE-2013-3528. Notes: All CVE users should reference CVE-2013-3528 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20130402)  None (candidate not yet proposed)    View
62952  CVE-2013-3005  Candidate  The TFTP client in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, when RBAC is enabled, allows remote authenticated users to bypass intended file-ownership restrictions, and read or overwrite arbitrary files, via unspecified vectors.  Assigned (20130412)  None (candidate not yet proposed)    View
63208  CVE-2013-3261  Candidate  Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.  Assigned (20130422)  None (candidate not yet proposed)    View
63464  CVE-2013-3517  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130508)  None (candidate not yet proposed)    View

Page 19111 of 20943, showing 5 records out of 104715 total, starting on record 95551, ending on 95555

Actions