CVE List

Id CVE No. Status Description Phase Votes Comments Actions
61685  CVE-2013-1738  Candidate  Use-after-free vulnerability in the JS_GetGlobalForScopeChain function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code by leveraging incorrect garbage collection in situations involving default compartments and frame-chain restoration.  Assigned (20130213)  None (candidate not yet proposed)    View
61941  CVE-2013-1994  Candidate  Multiple integer overflows in X.org libchromeXvMC and libchromeXvMCPro in openChrome 0.3.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) uniDRIOpenConnection and (2) uniDRIGetClientDriverName functions.  Assigned (20130219)  None (candidate not yet proposed)    View
62197  CVE-2013-2250  Candidate  Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, related to nested expressions.  Assigned (20130219)  None (candidate not yet proposed)    View
62453  CVE-2013-2506  Candidate  app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves.  Assigned (20130308)  None (candidate not yet proposed)    View
62709  CVE-2013-2762  Candidate  The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions via crafted configuration data.  Assigned (20130404)  None (candidate not yet proposed)    View

Page 19535 of 20943, showing 5 records out of 104715 total, starting on record 97671, ending on 97675

Actions