NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
39409  CVE-2013-3652  Cross-site scripting (XSS) vulnerability in data/class/pages/products/LC_Page_Products_List.php in LOCKON EC-CUBE 2.11.0 through 2.12.4 allows remote attackers to inject arbitrary web script or HTML via vectors involving the classcategory_id2 field, a different vulnerability than CVE-2013-3653.    4.3  Medium  2017-01-18  2013-10-11  View
39665  CVE-2013-3969  The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.    6.5  Medium  2017-01-18  2013-10-02  View
39921  CVE-2013-4294  The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token.    Medium  2017-01-18  2013-10-30  View
40177  CVE-2013-4594  The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment.    4.3  Medium  2017-01-18  2014-10-30  View
40433  CVE-2013-4949  Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in the upload form"s directory in data/.    6.8  Medium  2017-01-18  2013-07-30  View

Page 16808 of 17672, showing 5 records out of 88360 total, starting on record 84036, ending on 84040

Actions