CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63213  CVE-2013-3266  Candidate  The nfsrvd_readdir function in sys/fs/nfsserver/nfs_nfsdport.c in the new NFS server in FreeBSD 8.0 through 9.1-RELEASE-p3 does not verify that a READDIR request is for a directory node, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by specifying a plain file instead of a directory.  Assigned (20130423)  None (candidate not yet proposed)    View
63469  CVE-2013-3522  Candidate  SQL injection vulnerability in index.php/ajax/api/reputation/vote in vBulletin 5.0.0 Beta 11, 5.0.0 Beta 28, and earlier allows remote authenticated users to execute arbitrary SQL commands via the nodeid parameter.  Assigned (20130510)  None (candidate not yet proposed)    View
63725  CVE-2013-3778  Candidate  Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Help.  Assigned (20130603)  None (candidate not yet proposed)    View
63981  CVE-2013-4034  Candidate  IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.  Assigned (20130607)  None (candidate not yet proposed)    View
64237  CVE-2013-4290  Candidate  Stack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified impact via unknown vectors to (1) lib/openjp3d/opj_jp3d_compress.c, (2) bin/jp3d/convert.c, or (3) lib/openjp3d/event.c.  Assigned (20130612)  None (candidate not yet proposed)    View

Page 19518 of 20943, showing 5 records out of 104715 total, starting on record 97586, ending on 97590

Actions