CVE List

Id CVE No. Status Description Phase Votes Comments Actions
62445  CVE-2013-2498  Candidate  SQL injection vulnerability in the login page in flexycms/modules/user/user_manager.php in SimpleHRM 2.3, 2.2, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to index.php/user/setLogin.  Assigned (20130307)  None (candidate not yet proposed)    View
62701  CVE-2013-2754  Candidate  Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a request to admin/users/add/user/do/.  Assigned (20130403)  None (candidate not yet proposed)    View
62957  CVE-2013-3010  Candidate  Unspecified vulnerability in the Java Runtime Environment (JRE) in IBM Java 6.0.1 before 6.0.1 SR6 and 7 before 7 SR5 allows remote attackers to affect confidentiality, availability, and integrity via unknown vectors, a different vulnerability than CVE-2013-3007.  Assigned (20130412)  None (candidate not yet proposed)    View
63213  CVE-2013-3266  Candidate  The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new NFS server in FreeBSD 8.0 through 9.1-RELEASE-p3 does not verify that a READDIR request is for a directory node, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by specifying a plain file instead of a directory.  Assigned (20130423)  None (candidate not yet proposed)    View
63469  CVE-2013-3522  Candidate  SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter.  Assigned (20130510)  None (candidate not yet proposed)    View

Page 19499 of 20943, showing 5 records out of 104715 total, starting on record 97491, ending on 97495

Actions