NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
36889 | CVE-2013-0581 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Business Process Manager (BPM) 7.5.1.x, 8.0.0.x, and 8.0.1 before FP1 allow remote authenticated users to inject arbitrary web script or HTML via vectors involving (1) ProcessPortal/jsp/socialPortal/dashboard.jsp, (2) teamworks/executeServiceByName, (3) portal/jsp/viewAdHocReportWizard.do, or (4) rest/bpm/wle/v1/process. | 2 | 3.5 | Low | 2017-01-18 | 2013-07-08 | View | |
37145 | CVE-2013-0876 | Multiple integer overflows in the (1) old_codec37 and (2) old_codec47 functions in libavcodec/sanm.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via crafted LucasArts Smush data, which triggers an out-of-bounds array access. | 2 | 9.3 | High | 2017-01-18 | 2016-12-02 | View | |
37401 | CVE-2013-1153 | Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCue84676. | 2 | 6.8 | Medium | 2017-01-18 | 2013-03-08 | View | |
37657 | CVE-2013-1464 | Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-07 | View | |
37913 | CVE-2013-1762 | stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow. | 2 | 6.6 | Medium | 2017-01-18 | 2014-01-17 | View |
Page 1538 of 17672, showing 5 records out of 88360 total, starting on record 7686, ending on 7690