CVE List

Id CVE No. Status Description Phase Votes Comments Actions
60399  CVE-2013-0452  Candidate  Cross-site request forgery (CSRF) vulnerability in the Software Use Analysis (SUA) application before 1.3.3 in IBM Tivoli Endpoint Manager 8.2 allows remote attackers to hijack the authentication of arbitrary users via a web site that contains crafted Flash Action Message Format (AMF) messages.  Assigned (20121216)  None (candidate not yet proposed)    View
60655  CVE-2013-0708  Candidate  Cross-site scripting (XSS) vulnerability in dopvCOMET* 0009b allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header, which is not properly handled during display of the access log.  Assigned (20121228)  None (candidate not yet proposed)    View
60911  CVE-2013-0964  Candidate  The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and copyout arguments, which allows local users to bypass intended pointer restrictions and access locations in the first kernel-memory page by specifying a length of less than one page.  Assigned (20130110)  None (candidate not yet proposed)    View
61167  CVE-2013-1220  Candidate  The CallServer component in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to cause a denial of service (call-acceptance outage) via malformed SIP INVITE messages, aka Bug ID CSCua65148.  Assigned (20130111)  None (candidate not yet proposed)    View
61423  CVE-2013-1476  Candidate  Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to CORBA, a different vulnerability than CVE-2013-0441 and CVE-2013-1475. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass Java sandbox restrictions via "certain value handler constructors."  Assigned (20130130)  None (candidate not yet proposed)    View

Page 19670 of 20943, showing 5 records out of 104715 total, starting on record 98346, ending on 98350

Actions