CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63225  CVE-2013-3278  Candidate  EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local users to obtain sensitive information by reading the management-server configuration file.  Assigned (20130426)  None (candidate not yet proposed)    View
63481  CVE-2013-3534  Candidate  Cross-site scripting (XSS) vulnerability in the aiContactSafe component before 2.0.21 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20130513)  None (candidate not yet proposed)    View
63737  CVE-2013-3790  Candidate  Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors related to Privileged Account.  Assigned (20130603)  None (candidate not yet proposed)    View
63993  CVE-2013-4046  Candidate  Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.  Assigned (20130607)  None (candidate not yet proposed)    View
64249  CVE-2013-4302  Candidate  (1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php in includes/api/ in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow remote attackers to obtain CSRF tokens and bypass the cross-site request forgery (CSRF) protection mechanism via a JSONP request to wiki/api.php.  Assigned (20130612)  None (candidate not yet proposed)    View

Page 20464 of 20943, showing 5 records out of 104715 total, starting on record 102316, ending on 102320

Actions