CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
64492 | CVE-2013-4545 | Candidate | cURL and libcurl 7.18.0 through 7.32.0, when built with OpenSSL, disables the certificate CN and SAN name field verification (CURLOPT_SSL_VERIFYHOST) when the digital signature verification (CURLOPT_SSL_VERIFYPEER) is disabled, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64748 | CVE-2013-4801 | Candidate | Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1736. | Assigned (20130712) | None (candidate not yet proposed) | View | |
65004 | CVE-2013-5057 | Candidate | hxds.dll in Microsoft Office 2007 SP3 and 2010 SP1 and SP2 does not implement the ASLR protection mechanism, which makes it easier for remote attackers to execute arbitrary code via a crafted COM component on a web site that is visited with Internet Explorer, as exploited in the wild in December 2013, aka "HXDS ASLR Vulnerability." | Assigned (20130806) | None (candidate not yet proposed) | View | |
65260 | CVE-2013-5313 | Candidate | Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify arbitrary user accounts via an edit user action. | Assigned (20130819) | None (candidate not yet proposed) | View | |
65516 | CVE-2013-5569 | Candidate | SQL injection vulnerability in the Slideshare extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Assigned (20130823) | None (candidate not yet proposed) | View |
Page 19442 of 20943, showing 5 records out of 104715 total, starting on record 97206, ending on 97210