NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
40153  CVE-2013-4562  The omniauth-facebook gem 1.4.1 before 1.5.0 does not properly store the session parameter, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks via the state parameter.    6.8  Medium  2017-01-18  2014-05-14  View
40409  CVE-2013-4925  Integer signedness error in epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a crafted packet.    Medium  2017-01-18  2014-09-23  View
40665  CVE-2013-5349  Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a large JPEG tag value and a small size.    7.5  High  2017-01-18  2014-04-25  View
40921  CVE-2013-5655  Directory traversal vulnerability in the FTP server in YingZhi Python Programming Language for iOS 1.9 allows remote attackers to read and possibly write arbitrary files via a .. (dot dot) in the default URI.    6.4  Medium  2017-01-18  2014-05-15  View
41177  CVE-2013-5963  Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.    6.8  Medium  2017-01-18  2013-10-11  View

Page 15350 of 17672, showing 5 records out of 88360 total, starting on record 76746, ending on 76750

Actions