CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63480  CVE-2013-3533  Candidate  Multiple SQL injection vulnerabilities in Virtual Access Monitor 3.10.17 and earlier allow attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20130510)  None (candidate not yet proposed)    View
63736  CVE-2013-3789  Candidate  Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.  Assigned (20130603)  None (candidate not yet proposed)    View
63992  CVE-2013-4045  Candidate  Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20130607)  None (candidate not yet proposed)    View
64248  CVE-2013-4301  Candidate  includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to obtain sensitive information via a "<" (open angle bracket) character in the lang parameter to w/load.php, which reveals the installation path in an error message.  Assigned (20130612)  None (candidate not yet proposed)    View
64504  CVE-2013-4557  Candidate  The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connect parameter.  Assigned (20130612)  None (candidate not yet proposed)    View

Page 20381 of 20943, showing 5 records out of 104715 total, starting on record 101901, ending on 101905

Actions