NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 36269 | CVE-2014-9649 | Cross-site scripting (XSS) vulnerability in the management plugin in RabbitMQ 2.1.0 through 3.4.x before 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the path info to api/, which is not properly handled in an error message. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-02 | View | |
| 36781 | CVE-2013-0438 | Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11 and 6 through Update 38 allows remote attackers to affect confidentiality via unknown vectors related to Deployment. | 2 | 4.3 | Medium | 2017-01-18 | 2013-12-05 | View | |
| 37037 | CVE-2013-0747 | The gPluginHandler.handleEvent function in the plugin handler in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 does not properly enforce the Same Origin Policy, which allows remote attackers to conduct clickjacking attacks via crafted JavaScript code that listens for a mutation event. | 2 | 6.8 | Medium | 2017-01-18 | 2013-11-02 | View | |
| 37293 | CVE-2013-1027 | Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package"s installation after encountering a revoked certificate, which might allow user-assisted remote attackers to execute arbitrary code via a crafted package. | 2 | 6.8 | Medium | 2017-01-18 | 2013-09-18 | View | |
| 37805 | CVE-2013-1629 | pip before 1.3 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to a "pip install" operation. | 2 | 6.8 | Medium | 2017-01-18 | 2013-09-24 | View |
Page 14754 of 17672, showing 5 records out of 88360 total, starting on record 73766, ending on 73770