CVE List

Id CVE No. Status Description Phase Votes Comments Actions
61418  CVE-2013-1471  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User Preferences or (2) the User name field for the Personal Black/White List in the AntiSpam section.  Assigned (20130130)  None (candidate not yet proposed)    View
61674  CVE-2013-1727  Candidate  Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.  Assigned (20130213)  None (candidate not yet proposed)    View
61930  CVE-2013-1983  Candidate  Integer overflow in X.org libXfixes 5.0 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XFixesGetCursorImage function.  Assigned (20130219)  None (candidate not yet proposed)    View
62186  CVE-2013-2239  Candidate  vzkernel before 042stab080.2 in the OpenVZ modification for the Linux kernel 2.6.32 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via (1) a crafted ploop driver ioctl call, related to the ploop_getdevice_ioc function in drivers/block/ploop/dev.c, or (2) a crafted quotactl system call, related to the compat_quotactl function in fs/quota/quota.c.  Assigned (20130219)  None (candidate not yet proposed)    View
62442  CVE-2013-2495  Candidate  The iff_read_header function in iff.c in libavformat in FFmpeg through 1.1.3 does not properly handle data sizes for Interchange File Format (IFF) data during operations involving a CMAP chunk or a video codec, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) or possibly have unspecified other impact via a crafted header.  Assigned (20130307)  None (candidate not yet proposed)    View

Page 19285 of 20943, showing 5 records out of 104715 total, starting on record 96421, ending on 96425

Actions