NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
37350 | CVE-2013-1096 | Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId. | 2 | 4.3 | Medium | 2017-01-18 | 2015-07-29 | View | |
37862 | CVE-2013-1698 | The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements. | 2 | 4.3 | Medium | 2017-01-18 | 2013-11-02 | View | |
38118 | CVE-2013-1995 | X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-20 | View | |
38374 | CVE-2013-2309 | Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the "mobile version color scheme." | 2 | 4.3 | Medium | 2017-01-18 | 2013-06-18 | View | |
38886 | CVE-2013-2994 | IBM WebSphere Commerce 7.0 Feature Pack 4 and Feature Pack 5 incorrectly maintains a valid session after unspecified interaction with REST services, which allows remote attackers to issue REST requests in the context of an arbitrary user"s active session via unknown vectors. | 2 | 6.4 | Medium | 2017-01-18 | 2013-08-01 | View |
Page 16777 of 17672, showing 5 records out of 88360 total, starting on record 83881, ending on 83885