NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
41210 | CVE-2013-6005 | Cross-site scripting (XSS) vulnerability in Cybozu Dezie before 8.1.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Cancel button. | 2 | 4.3 | Medium | 2017-01-18 | 2013-12-16 | View | |
41466 | CVE-2013-6408 | The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407. | 2 | 6.4 | Medium | 2017-01-18 | 2014-07-17 | View | |
41722 | CVE-2013-6858 | Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page. | 2 | 1.9 | Low | 2017-01-18 | 2016-12-21 | View | |
41978 | CVE-2013-7240 | Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter. | 2 | 5 | Medium | 2017-01-18 | 2014-02-25 | View | |
42234 | CVE-2012-0091 | Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.52.05 allows remote authenticated users to affect integrity and availability via unknown vectors related to Upgrade Change Assistance. | 2 | 2.7 | Low | 2017-01-19 | 2012-01-30 | View |
Page 16965 of 17672, showing 5 records out of 88360 total, starting on record 84821, ending on 84825