CVE List

Id CVE No. Status Description Phase Votes Comments Actions
64492  CVE-2013-4545  Candidate  cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.  Assigned (20130612)  None (candidate not yet proposed)    View
64748  CVE-2013-4801  Candidate  Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1736.  Assigned (20130712)  None (candidate not yet proposed)    View
65004  CVE-2013-5057  Candidate  hxds.dll in Microsoft Office 2007 SP3 and 2010 SP1 and SP2 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted COM component on a web site that is visited with Internet Explorer, as exploited in the wild in December 2013, aka "HXDS ASLR Vulnerability."  Assigned (20130806)  None (candidate not yet proposed)    View
65260  CVE-2013-5313  Candidate  Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify arbitrary user accounts via an edit user action.  Assigned (20130819)  None (candidate not yet proposed)    View
65516  CVE-2013-5569  Candidate  SQL injection vulnerability in the Slideshare extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20130823)  None (candidate not yet proposed)    View

Page 19442 of 20943, showing 5 records out of 104715 total, starting on record 97206, ending on 97210

Actions