NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
37076 | CVE-2013-0786 | The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query. | 2 | 5 | Medium | 2017-01-18 | 2013-12-13 | View | |
38356 | CVE-2013-2287 | Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2014-04-04 | View | |
38612 | CVE-2013-2633 | Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obtain sensitive information by leveraging the logging of parameters. | 2 | 5 | Medium | 2017-01-18 | 2013-04-09 | View | |
40148 | CVE-2013-4556 | Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-07 | View | |
40404 | CVE-2013-4920 | The P1 dissector in Wireshark 1.10.x before 1.10.1 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | 2 | 5 | Medium | 2017-01-18 | 2014-09-23 | View |
Page 16131 of 17672, showing 5 records out of 88360 total, starting on record 80651, ending on 80655