CVE List

Id CVE No. Status Description Phase Votes Comments Actions
59902  CVE-2012-6659  Candidate  Cross-site scripting (XSS) vulnerability in the admin interface in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.  Assigned (20140919)  None (candidate not yet proposed)    View
60158  CVE-2013-0211  Candidate  Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer overflow.  Assigned (20121206)  None (candidate not yet proposed)    View
60414  CVE-2013-0467  Candidate  IBM Eclipse Help System (IEHS), as used in IBM Data Studio 3.1 and 3.1.1 and other products, allows remote authenticated users to read source code via a crafted URL.  Assigned (20121216)  None (candidate not yet proposed)    View
60670  CVE-2013-0723  Candidate  Multiple heap-based buffer overflows in etxrw.dll in Kingsoft Spreadsheets 2012 8.1.0.3030 allow remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via a crafted spreadsheet file.  Assigned (20130102)  None (candidate not yet proposed)    View
60926  CVE-2013-0979  Candidate  lockdownd in Lockdown in Apple iOS before 6.1.3 does not properly consider file types during the permission-setting step of a backup restoration, which allows local users to change the permissions of arbitrary files via a backup that contains a pathname with a symlink.  Assigned (20130110)  None (candidate not yet proposed)    View

Page 20826 of 20943, showing 5 records out of 104715 total, starting on record 104126, ending on 104130

Actions