CVE List

Id CVE No. Status Description Phase Votes Comments Actions
60165  CVE-2013-0218  Candidate  The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.  Assigned (20121206)  None (candidate not yet proposed)    View
60421  CVE-2013-0474  Candidate  The Manual Explore browser plug-in in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to discover test Platform Authentication credentials via a crafted web site.  Assigned (20121216)  None (candidate not yet proposed)    View
60677  CVE-2013-0730  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) language parameter to application/modules/admin/controllers/LanguagesController.php or (2) user parameter to application/modules/admin/controllers/UserController.php.  Assigned (20130102)  None (candidate not yet proposed)    View
60933  CVE-2013-0986  Candidate  Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted enof atoms in a movie file.  Assigned (20130110)  None (candidate not yet proposed)    View
61189  CVE-2013-1242  Candidate  Memory leak in the web framework in the server in Cisco Unified Presence (CUP) allows remote attackers to cause a denial of service (memory consumption) via malformed TCP packets, aka Bug ID CSCug38080.  Assigned (20130111)  None (candidate not yet proposed)    View

Page 497 of 20943, showing 5 records out of 104715 total, starting on record 2481, ending on 2485

Actions