CVE List

Id CVE No. Status Description Phase Votes Comments Actions
60401  CVE-2013-0454  Candidate  The SMB2 implementation in Samba 3.6.x before 3.6.6, as used on the IBM Storwize V7000 Unified 1.3 before 1.3.2.3 and 1.4 before 1.4.0.1 and possibly other products, does not properly enforce CIFS share attributes, which allows remote authenticated users to (1) write to a read-only share; (2) trigger data-integrity problems related to the oplock, locking, coherency, or leases attribute; or (3) have an unspecified impact by leveraging incorrect handling of the browseable or "hide unreadable" parameter.  Assigned (20121216)  None (candidate not yet proposed)    View
60657  CVE-2013-0710  Candidate  Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document.  Assigned (20121228)  None (candidate not yet proposed)    View
60913  CVE-2013-0966  Candidate  The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.  Assigned (20130110)  None (candidate not yet proposed)    View
61169  CVE-2013-1222  Candidate  The Tomcat Web Management feature in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly configure Tomcat components, which allows remote attackers to launch arbitrary custom web applications via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38379.  Assigned (20130111)  None (candidate not yet proposed)    View
61425  CVE-2013-1478  Candidate  Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" that can trigger an integer overflow and memory corruption.  Assigned (20130130)  None (candidate not yet proposed)    View

Page 19824 of 20943, showing 5 records out of 104715 total, starting on record 99116, ending on 99120

Actions