NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40943 | CVE-2013-5694 | SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands via the service_selection parameter. | 2 | 7.5 | High | 2017-01-18 | 2013-11-06 | View | |
41199 | CVE-2013-5994 | data/class/pages/mypage/LC_Page_Mypage_DeliveryAddr.php in LOCKON EC-CUBE 2.11.2 through 2.13.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message. | 2 | 5 | Medium | 2017-01-18 | 2013-11-21 | View | |
41455 | CVE-2013-6397 | Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. NOTE: this can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries. | 2 | 4.3 | Medium | 2017-01-18 | 2015-10-23 | View | |
41711 | CVE-2013-6832 | The nand_ioctl function in sys/dev/nand/nand_geom.c in the nand driver in the kernel in FreeBSD 10 and earlier does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call. | 2 | 4.9 | Medium | 2017-01-18 | 2013-11-24 | View | |
41967 | CVE-2013-7223 | Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to the lack of a protect_from_forgery line in app/controllers/application_controller.rb. | 2 | 6.8 | Medium | 2017-01-18 | 2014-01-03 | View |
Page 16566 of 17672, showing 5 records out of 88360 total, starting on record 82826, ending on 82830