CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63476  CVE-2013-3529  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in user/obits.php in the WP FuneralPress plugin before 1.1.7 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) message, (2) photo-message, or (3) youtube-message parameter.  Assigned (20130510)  None (candidate not yet proposed)    View
63732  CVE-2013-3785  Candidate  Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Career"s Home.  Assigned (20130603)  None (candidate not yet proposed)    View
63988  CVE-2013-4041  Candidate  Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to access restricted classes via unspecified vectors.  Assigned (20130607)  None (candidate not yet proposed)    View
64244  CVE-2013-4297  Candidate  The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.  Assigned (20130612)  None (candidate not yet proposed)    View
64500  CVE-2013-4553  Candidate  The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same order, which allows local guest administrators to cause a denial of service (host deadlock).  Assigned (20130612)  None (candidate not yet proposed)    View

Page 20067 of 20943, showing 5 records out of 104715 total, starting on record 100331, ending on 100335

Actions