CVE List

Id CVE No. Status Description Phase Votes Comments Actions
60146  CVE-2013-0199  Candidate  The default LDAP ACIs in FreeIPA 3.0 before 3.1.2 do not restrict access to the (1) ipaNTTrustAuthIncoming and (2) ipaNTTrustAuthOutgoing attributes, which allow remote attackers to obtain the Cross-Realm Kerberos Trust key via unspecified vectors.  Assigned (20121206)  None (candidate not yet proposed)    View
60402  CVE-2013-0455  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2.4 and Sterling File Gateway allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20121216)  None (candidate not yet proposed)    View
60658  CVE-2013-0711  Candidate  IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to cause a denial of service (daemon outage) via a crafted authentication request.  Assigned (20121228)  None (candidate not yet proposed)    View
60914  CVE-2013-0967  Candidate  CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site.  Assigned (20130110)  None (candidate not yet proposed)    View
61170  CVE-2013-1223  Candidate  The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via a crafted (1) HTTP or (2) HTTPS request, aka Bug ID CSCub38372.  Assigned (20130111)  None (candidate not yet proposed)    View

Page 19901 of 20943, showing 5 records out of 104715 total, starting on record 99501, ending on 99505

Actions