CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
63995 | CVE-2013-4048 | Candidate | Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving addition of script to a page. | Assigned (20130607) | None (candidate not yet proposed) | View | |
64251 | CVE-2013-4304 | Candidate | The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64507 | CVE-2013-4560 | Candidate | Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64763 | CVE-2013-4816 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20130712) | None (candidate not yet proposed) | View | |
65019 | CVE-2013-5072 | Candidate | Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability." | Assigned (20130806) | None (candidate not yet proposed) | View |
Page 20598 of 20943, showing 5 records out of 104715 total, starting on record 102986, ending on 102990