NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
40719  CVE-2013-5421  Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote attackers to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form.    4.3  Medium  2017-01-18  2013-12-26  View
40975  CVE-2013-5739  The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.    3.5  Low  2017-01-18  2013-09-26  View
41231  CVE-2013-6029  Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code via a malformed .SVT file.    6.8  Medium  2017-01-18  2016-12-30  View
41487  CVE-2013-6431  The fib6_add function in net/ipv6/ip6_fib.c in the Linux kernel before 3.11.5 does not properly implement error-code encoding, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for an IPv6 SIOCADDRT ioctl call.    4.7  Medium  2017-01-18  2014-03-05  View
41743  CVE-2013-6884  The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges.    10  High  2017-01-18  2014-02-24  View

Page 1420 of 17672, showing 5 records out of 88360 total, starting on record 7096, ending on 7100

Actions