NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
37076  CVE-2013-0786  The Bugzilla::Search::build_subselect function in Bugzilla 2.x and 3.x before 3.6.13 and 3.7.x and 4.0.x before 4.0.10 generates different error messages for invalid product queries depending on whether a product exists, which allows remote attackers to discover private product names by using debug mode for a query.    Medium  2017-01-18  2013-12-13  View
38356  CVE-2013-2287  Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.    4.3  Medium  2017-01-18  2014-04-04  View
38612  CVE-2013-2633  Piwik before 1.11 accepts input from a POST request instead of a GET request in unspecified circumstances, which might allow attackers to obtain sensitive information by leveraging the logging of parameters.    Medium  2017-01-18  2013-04-09  View
40148  CVE-2013-4556  Cross-site scripting (XSS) vulnerability in the author page (prive/formulaires/editer_auteur.php) in SPIP before 2.1.24 and 3.0.x before 3.0.12 allows remote attackers to inject arbitrary web script or HTML via the url_site parameter.    4.3  Medium  2017-01-18  2016-12-07  View
40404  CVE-2013-4920  The P1 dissector in Wireshark 1.10.x before 1.10.1 does not properly initialize a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.    Medium  2017-01-18  2014-09-23  View

Page 16131 of 17672, showing 5 records out of 88360 total, starting on record 80651, ending on 80655

Actions