CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63995  CVE-2013-4048  Candidate  Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving addition of script to a page.  Assigned (20130607)  None (candidate not yet proposed)    View
64251  CVE-2013-4304  Candidate  The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.  Assigned (20130612)  None (candidate not yet proposed)    View
64507  CVE-2013-4560  Candidate  Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.  Assigned (20130612)  None (candidate not yet proposed)    View
64763  CVE-2013-4816  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130712)  None (candidate not yet proposed)    View
65019  CVE-2013-5072  Candidate  Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."  Assigned (20130806)  None (candidate not yet proposed)    View

Page 20598 of 20943, showing 5 records out of 104715 total, starting on record 102986, ending on 102990

Actions