CVE List

Id CVE No. Status Description Phase Votes Comments Actions
60148  CVE-2013-0201  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to core/lostpassword/templates/resetpassword.php, (2) mime parameter to apps/files/ajax/mimeicon.php, or (3) token parameter to apps/gallery/sharing.php.  Assigned (20121206)  None (candidate not yet proposed)    View
60404  CVE-2013-0457  Candidate  Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to a uisessionid.  Assigned (20121216)  None (candidate not yet proposed)    View
60660  CVE-2013-0713  Candidate  IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a crafted pty request.  Assigned (20121228)  None (candidate not yet proposed)    View
60916  CVE-2013-0969  Candidate  Login Window in Apple Mac OS X before 10.8.3 does not prevent application launching with the VoiceOver feature, which allows physically proximate attackers to bypass authentication and make arbitrary System Preferences changes via unspecified use of the keyboard.  Assigned (20130110)  None (candidate not yet proposed)    View
61172  CVE-2013-1225  Candidate  Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCub38366.  Assigned (20130111)  None (candidate not yet proposed)    View

Page 20058 of 20943, showing 5 records out of 104715 total, starting on record 100286, ending on 100290

Actions