CVE List

Id CVE No. Status Description Phase Votes Comments Actions
63483  CVE-2013-3536  Candidate  SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote attackers to execute arbitrary SQL commands via the hash parameter.  Assigned (20130513)  None (candidate not yet proposed)    View
63739  CVE-2013-3792  Candidate  Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.18, 4.0.20, 4.1.28, and 4.2.18 allows local users to affect availability via unknown vectors related to Core.  Assigned (20130603)  None (candidate not yet proposed)    View
63995  CVE-2013-4048  Candidate  Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving addition of script to a page.  Assigned (20130607)  None (candidate not yet proposed)    View
64251  CVE-2013-4304  Candidate  The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.  Assigned (20130612)  None (candidate not yet proposed)    View
64507  CVE-2013-4560  Candidate  Use-after-free vulnerability in lighttpd before 1.4.33 allows remote attackers to cause a denial of service (segmentation fault and crash) via unspecified vectors that trigger FAMMonitorDirectory failures.  Assigned (20130612)  None (candidate not yet proposed)    View

Page 20624 of 20943, showing 5 records out of 104715 total, starting on record 103116, ending on 103120

Actions