CVE List

Id CVE No. Status Description Phase Votes Comments Actions
61427  CVE-2013-1480  Candidate  Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, 6 through Update 38, 5.0 through Update 38, and 1.4.2_40 and earlier, and OpenJDK 6 and 7, allows remote attackers to affect confidentiality, integrity, and availability via vectors related to AWT. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "insufficient validation of raster parameters" in awt_parseImage.c, which triggers memory corruption.  Assigned (20130130)  None (candidate not yet proposed)    View
61683  CVE-2013-1736  Candidate  The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to improperly establishing parent-child relationships of range-request nodes.  Assigned (20130213)  None (candidate not yet proposed)    View
61939  CVE-2013-1992  Candidate  Multiple integer overflows in X.org libdmx 1.1.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) DMXGetScreenAttributes, (2) DMXGetWindowAttributes, and (3) DMXGetInputAttributes functions.  Assigned (20130219)  None (candidate not yet proposed)    View
62195  CVE-2013-2248  Candidate  Multiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a parameter using the (1) redirect: or (2) redirectAction: prefix.  Assigned (20130219)  None (candidate not yet proposed)    View
62451  CVE-2013-2504  Candidate  Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows remote attackers to inject arbitrary web script or HTML via the query string.  Assigned (20130307)  None (candidate not yet proposed)    View

Page 19979 of 20943, showing 5 records out of 104715 total, starting on record 99891, ending on 99895

Actions