CVE List

Id CVE No. Status Description Phase Votes Comments Actions
59382  CVE-2012-6139  Candidate  libxslt before 1.1.28 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an (1) empty match attribute in a XSL key to the xsltAddKey function in keys.c or (2) uninitialized variable to the xsltDocumentFunction function in functions.c.  Assigned (20121206)  None (candidate not yet proposed)    View
59638  CVE-2012-6395  Candidate  Cisco Adaptive Security Appliances (ASA) devices with firmware 8.4 do not properly validate unspecified input related to UNC share pathnames, which allows remote authenticated users to cause a denial of service (device crash) via unknown vectors, aka Bug ID CSCuc65775.  Assigned (20121216)  None (candidate not yet proposed)    View
59894  CVE-2012-6651  Candidate  Multiple directory traversal vulnerabilities in the Vitamin plugin before 1.1.0 for WordPress allow remote attackers to access arbitrary files via a .. (dot dot) in the path parameter to (1) add_headers.php or (2) minify.php.  Assigned (20140728)  None (candidate not yet proposed)    View
60150  CVE-2013-0203  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20121206)  None (candidate not yet proposed)    View
60406  CVE-2013-0459  Candidate  Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20121216)  None (candidate not yet proposed)    View

Page 20223 of 20943, showing 5 records out of 104715 total, starting on record 101111, ending on 101115

Actions