NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 39646 | CVE-2013-3938 | Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which triggers a heap-based buffer overflow. | 2 | 9.3 | High | 2017-01-18 | 2014-03-19 | View | |
| 39902 | CVE-2013-4272 | The BOTCHA Spam Prevention module 7.x-1.x before 7.x-1.6, 7.x-2.x before 7.x-2.1, and 7.x-3.x before 7.x-3.3 for Drupal, when the debugging level is set to 5 or 6, logs the content of submitted forms, which allows context-dependent users to obtain sensitive information such as usernames and passwords by reading the log file. | 2 | 4.3 | Medium | 2017-01-18 | 2013-09-05 | View | |
| 40158 | CVE-2013-4567 | Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a (backspace) character in CSS. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View | |
| 40414 | CVE-2013-4930 | The dissect_dvbci_tpdu_hdr function in epan/dissectors/packet-dvbci.c in the DVB-CI dissector in Wireshark 1.8.x before 1.8.9 and 1.10.x before 1.10.1 does not validate a certain length value before decrementing it, which allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted packet. | 2 | 5 | Medium | 2017-01-18 | 2014-09-23 | View | |
| 40670 | CVE-2013-5354 | Multiple SQL injection vulnerabilities in Sharetronix 3.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) fb_user_id or (2) tw_user_id parameter to signup. | 2 | 7.5 | High | 2017-01-18 | 2014-06-18 | View |
Page 15653 of 17672, showing 5 records out of 88360 total, starting on record 78261, ending on 78265