CVE List

Id CVE No. Status Description Phase Votes Comments Actions
61689  CVE-2013-1742  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) sortkey parameter.  Assigned (20130213)  None (candidate not yet proposed)    View
61945  CVE-2013-1998  Candidate  Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.  Assigned (20130219)  None (candidate not yet proposed)    View
62201  CVE-2013-2254  Candidate  The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root node, which allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.  Assigned (20130219)  None (candidate not yet proposed)    View
62457  CVE-2013-2510  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130308)  None (candidate not yet proposed)    View
62713  CVE-2013-2766  Candidate  Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 4.3.0 through 4.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20130407)  None (candidate not yet proposed)    View

Page 20460 of 20943, showing 5 records out of 104715 total, starting on record 102296, ending on 102300

Actions