NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 40410 | CVE-2013-4926 | epan/dissectors/packet-dcom-sysact.c in the DCOM ISystemActivator dissector in Wireshark 1.10.x before 1.10.1 does not properly determine whether there is remaining packet data to process, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | 2 | 5 | Medium | 2017-01-18 | 2014-09-23 | View | |
| 40666 | CVE-2013-5350 | The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct PHP object injection attacks, and execute arbitrary PHP code, via a crafted serialized object. | 2 | 7.5 | High | 2017-01-18 | 2014-01-24 | View | |
| 40922 | CVE-2013-5660 | Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file. | 2 | 9.3 | High | 2017-01-18 | 2014-04-25 | View | |
| 41178 | CVE-2013-5964 | Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "Administer flags" permission to inject arbitrary web script or HTML via the flag title. | 2 | 2.1 | Low | 2017-01-18 | 2013-10-10 | View | |
| 41434 | CVE-2013-6375 | Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter." | 2 | 7.9 | High | 2017-01-18 | 2017-01-06 | View |
Page 15411 of 17672, showing 5 records out of 88360 total, starting on record 77051, ending on 77055