CVE List

Id CVE No. Status Description Phase Votes Comments Actions
64495  CVE-2013-4548  Candidate  The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memory for a MAC context data structure, which allows remote authenticated users to bypass intended ForceCommand and login-shell restrictions via packet data that provides a crafted callback address.  Assigned (20130612)  None (candidate not yet proposed)    View
64751  CVE-2013-4804  Candidate  Unspecified vulnerability in HP Business Process Monitor 9.13.1 patch 1 and 9.22 patch 1 allows remote attackers to execute arbitrary code and obtain sensitive information via unknown vectors.  Assigned (20130712)  None (candidate not yet proposed)    View
65007  CVE-2013-5060  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130806)  None (candidate not yet proposed)    View
65263  CVE-2013-5316  Candidate  Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via an edit user action to cms/index.php.  Assigned (20130820)  None (candidate not yet proposed)    View
65519  CVE-2013-5572  Candidate  Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.  Assigned (20130823)  None (candidate not yet proposed)    View

Page 19661 of 20943, showing 5 records out of 104715 total, starting on record 98301, ending on 98305

Actions