NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
39868  CVE-2013-4223  The Gentoo Nullmailer package before 1.11-r2 uses world-readable permissions for /etc/nullmailer/remotes, which allows local users to obtain SMTP authentication credentials by reading the file.    Medium  2017-01-18  2014-05-27  View
40380  CVE-2013-4872  Google Glass before XE6 does not properly restrict the processing of QR codes, which allows physically proximate attackers to modify the configuration or redirect users to arbitrary web sites via a crafted symbol, as demonstrated by selecting a Wi-Fi access point in order to conduct a man-in-the-middle attack.    6.9  Medium  2017-01-18  2013-08-06  View
41148  CVE-2013-5918  Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.    4.3  Medium  2017-01-18  2013-09-23  View
41916  CVE-2013-7110  Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-2073.    4.3  Medium  2017-01-18  2014-05-02  View
42940  CVE-2012-0875  SystemTap 1.7, 1.6.7, and probably other versions, when unprivileged mode is enabled, allows local users to obtain sensitive information from kernel memory or cause a denial of service (kernel panic and crash) via vectors related to crafted DWARF data, which triggers a read of an invalid pointer.    5.4  Medium  2017-01-19  2014-02-24  View

Page 15288 of 17672, showing 5 records out of 88360 total, starting on record 76436, ending on 76440

Actions