CVE List

Id CVE No. Status Description Phase Votes Comments Actions
61960  CVE-2013-2013  Candidate  The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the process.  Assigned (20130219)  None (candidate not yet proposed)    View
62216  CVE-2013-2269  Candidate  The Sponsorship Confirmation functionality in Aruba Networks ClearPass 5.x, 6.0.1, and 6.0.2, and Amigopod/ClearPass Guest 3.0 through 3.9.7, allows remote attackers to bypass intended access restrictions and approve a request by sending a guest request, then using "parameter manipulation" in conjunction with information from a "default holding page" to discover the link that is used for sponsor approval of the guest request, then performing a direct request to that link.  Assigned (20130225)  None (candidate not yet proposed)    View
62472  CVE-2013-2525  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20130308)  None (candidate not yet proposed)    View
62728  CVE-2013-2781  Candidate  Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.  Assigned (20130411)  None (candidate not yet proposed)    View
62984  CVE-2013-3037  Candidate  Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors.  Assigned (20130412)  None (candidate not yet proposed)    View

Page 723 of 20943, showing 5 records out of 104715 total, starting on record 3611, ending on 3615

Actions