CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
63479 | CVE-2013-3532 | Candidate | SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter. | Assigned (20130510) | None (candidate not yet proposed) | View | |
63735 | CVE-2013-3788 | Candidate | Unspecified vulnerability in the Oracle iSupplier Portal component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Supplier Management. | Assigned (20130603) | None (candidate not yet proposed) | View | |
63991 | CVE-2013-4044 | Candidate | IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request. | Assigned (20130607) | None (candidate not yet proposed) | View | |
64247 | CVE-2013-4300 | Candidate | The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64503 | CVE-2013-4556 | Candidate | Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter. | Assigned (20130612) | None (candidate not yet proposed) | View |
Page 20289 of 20943, showing 5 records out of 104715 total, starting on record 101441, ending on 101445