CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63980  CVE-2013-4033  Candidate  IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority.  Assigned (20130607)  None (candidate not yet proposed)    View
64236  CVE-2013-4289  Candidate  Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigger a heap-based buffer overflow.  Assigned (20130612)  None (candidate not yet proposed)    View
64492  CVE-2013-4545  Candidate  cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.  Assigned (20130612)  None (candidate not yet proposed)    View
64748  CVE-2013-4801  Candidate  Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1736.  Assigned (20130712)  None (candidate not yet proposed)    View
65004  CVE-2013-5057  Candidate  hxds.dll in Microsoft Office 2007 SP3 and 2010 SP1 and SP2 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted COM component on a web site that is visited with Internet Explorer, as exploited in the wild in December 2013, aka "HXDS ASLR Vulnerability."  Assigned (20130806)  None (candidate not yet proposed)    View

Page 19431 of 20943, showing 5 records out of 104715 total, starting on record 97151, ending on 97155

Actions