CVE List

Id CVE No. Status Description Phase Votes Comments Actions
62187  CVE-2013-2240  Candidate  lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.  Assigned (20130219)  None (candidate not yet proposed)    View
62443  CVE-2013-2496  Candidate  The msrle_decode_8_16_24_32 function in msrledec.c in libavcodec in FFmpeg through 1.1.3 does not properly determine certain end pointers, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) or possibly have unspecified other impact via crafted Microsoft RLE data.  Assigned (20130307)  None (candidate not yet proposed)    View
62699  CVE-2013-2752  Candidate  Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to hijack the authentication of users.  Assigned (20130402)  None (candidate not yet proposed)    View
62955  CVE-2013-3008  Candidate  Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3006.  Assigned (20130412)  None (candidate not yet proposed)    View
63211  CVE-2013-3264  Candidate  The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2) campaign/editCampaign.php, which allows remote attackers to modify list or campaign data.  Assigned (20130422)  None (candidate not yet proposed)    View

Page 19363 of 20943, showing 5 records out of 104715 total, starting on record 96811, ending on 96815

Actions