CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
64506 | CVE-2013-4559 | Candidate | lighttpd before 1.4.33 does not check the return value of the (1) setuid, (2) setgid, or (3) setgroups functions, which might cause lighttpd to run as root if it is restarted and allows remote attackers to gain privileges, as demonstrated by multiple calls to the clone function that cause setuid to fail when the user process limit is reached. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64762 | CVE-2013-4815 | Candidate | Cross-site scripting (XSS) vulnerability in the web interface in HP ArcSight Enterprise Security Manager (ESM) before 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20130712) | None (candidate not yet proposed) | View | |
65018 | CVE-2013-5071 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20130806) | None (candidate not yet proposed) | View | |
65274 | CVE-2013-5327 | Candidate | MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | Assigned (20130820) | None (candidate not yet proposed) | View | |
65530 | CVE-2013-5583 | Candidate | Cross-site scripting (XSS) vulnerability in libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter. | Assigned (20130823) | None (candidate not yet proposed) | View |
Page 20542 of 20943, showing 5 records out of 104715 total, starting on record 102706, ending on 102710