NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
36589 | CVE-2013-0233 | Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts. | 2 | 6.8 | Medium | 2017-01-18 | 2013-05-01 | View | |
36845 | CVE-2013-0511 | Multiple SQL injection vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified parameters. | 2 | 6.5 | Medium | 2017-01-18 | 2013-03-29 | View | |
37357 | CVE-2013-1107 | The search function in Cisco Webex Social (formerly Cisco Quad) allows remote authenticated users to read files via unspecified parameters, aka Bug ID CSCud40235. | 2 | 4 | Medium | 2017-01-18 | 2013-02-07 | View | |
38125 | CVE-2013-2002 | Buffer overflow in X.org libXt 1.1.3 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the _XtResourceConfigurationEH function. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-20 | View | |
38381 | CVE-2013-2316 | The Yahoo! Browser application 1.4.4 and earlier for Android allows remote attackers to spoof the address bar via vectors related to URL display, a different vulnerability than CVE-2013-2307. | 2 | 5.8 | Medium | 2017-01-18 | 2013-06-04 | View |
Page 17009 of 17672, showing 5 records out of 88360 total, starting on record 85041, ending on 85045