CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
63480 | CVE-2013-3533 | Candidate | Multiple SQL injection vulnerabilities in Virtual Access Monitor 3.10.17 and earlier allow attackers to execute arbitrary SQL commands via unspecified vectors. | Assigned (20130510) | None (candidate not yet proposed) | View | |
63736 | CVE-2013-3789 | Candidate | Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | Assigned (20130603) | None (candidate not yet proposed) | View | |
63992 | CVE-2013-4045 | Candidate | Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20130607) | None (candidate not yet proposed) | View | |
64248 | CVE-2013-4301 | Candidate | includes/resourceloader/ResourceLoaderContext.php in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to obtain sensitive information via a "<" (open angle bracket) character in the lang parameter to w/load.php, which reveals the installation path in an error message. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64504 | CVE-2013-4557 | Candidate | The Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote attackers to execute arbitrary PHP via the connect parameter. | Assigned (20130612) | None (candidate not yet proposed) | View |
Page 20385 of 20943, showing 5 records out of 104715 total, starting on record 101921, ending on 101925