NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
36589  CVE-2013-0233  Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to cause incorrect results to be returned and bypass security checks via unknown vectors, as demonstrated by resetting passwords of arbitrary accounts.    6.8  Medium  2017-01-18  2013-05-01  View
36845  CVE-2013-0511  Multiple SQL injection vulnerabilities in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified parameters.    6.5  Medium  2017-01-18  2013-03-29  View
37357  CVE-2013-1107  The search function in Cisco Webex Social (formerly Cisco Quad) allows remote authenticated users to read files via unspecified parameters, aka Bug ID CSCud40235.    Medium  2017-01-18  2013-02-07  View
38125  CVE-2013-2002  Buffer overflow in X.org libXt 1.1.3 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the _XtResourceConfigurationEH function.    6.8  Medium  2017-04-27  2017-04-20  View
38381  CVE-2013-2316  The Yahoo! Browser application 1.4.4 and earlier for Android allows remote attackers to spoof the address bar via vectors related to URL display, a different vulnerability than CVE-2013-2307.    5.8  Medium  2017-01-18  2013-06-04  View

Page 17009 of 17672, showing 5 records out of 88360 total, starting on record 85041, ending on 85045

Actions