CVE List

Id CVE No. Status Description Phase Votes Comments Actions
64251  CVE-2013-4304  Candidate  The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.  Assigned (20130612)  None (candidate not yet proposed)    View
64507  CVE-2013-4560  Candidate  Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.  Assigned (20130612)  None (candidate not yet proposed)    View
64763  CVE-2013-4816  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130712)  None (candidate not yet proposed)    View
65019  CVE-2013-5072  Candidate  Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."  Assigned (20130806)  None (candidate not yet proposed)    View
65275  CVE-2013-5328  Candidate  Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors.  Assigned (20130820)  None (candidate not yet proposed)    View

Page 20014 of 20943, showing 5 records out of 104715 total, starting on record 100066, ending on 100070

Actions