CVE List

Id CVE No. Status Description Phase Votes Comments Actions
64506  CVE-2013-4559  Candidate  lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached.  Assigned (20130612)  None (candidate not yet proposed)    View
64762  CVE-2013-4815  Candidate  Cross-site scripting (XSS) vulnerability in the web interface in HP ArcSight Enterprise Security Manager (ESM) before 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20130712)  None (candidate not yet proposed)    View
65018  CVE-2013-5071  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130806)  None (candidate not yet proposed)    View
65274  CVE-2013-5327  Candidate  MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.  Assigned (20130820)  None (candidate not yet proposed)    View
65530  CVE-2013-5583  Candidate  Cross-site scripting (XSS) vulnerability in libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.  Assigned (20130823)  None (candidate not yet proposed)    View

Page 20542 of 20943, showing 5 records out of 104715 total, starting on record 102706, ending on 102710

Actions