NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 38066 | CVE-2013-1939 | The HTMLBrowser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a (backslash) character. | 2 | 5 | Medium | 2017-01-18 | 2014-03-26 | View | |
| 38834 | CVE-2013-2921 | Double free vulnerability in the ResourceFetcher::didLoadResource function in core/fetch/ResourceFetcher.cpp in the resource loader in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering certain callback processing during the reporting of a resource entry. | 2 | 6.8 | Medium | 2017-01-18 | 2014-03-05 | View | |
| 39090 | CVE-2013-3256 | Cross-site request forgery (CSRF) vulnerability in the Shareaholic SexyBookmarks plugin 6.1.4.0 for WordPress allows remote attackers to hijack the authentication of users for requests that "manipulate plugin settings." | 2 | 6.8 | Medium | 2017-01-18 | 2013-08-09 | View | |
| 39858 | CVE-2013-4213 | Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client. | 2 | 6.4 | Medium | 2017-01-18 | 2016-12-07 | View | |
| 40114 | CVE-2013-4517 | Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures. | 2 | 4.3 | Medium | 2017-01-18 | 2015-04-22 | View |
Page 14931 of 17672, showing 5 records out of 88360 total, starting on record 74651, ending on 74655