NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
41206 | CVE-2013-6001 | SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-18 | 2014-01-03 | View | |
41462 | CVE-2013-6404 | Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users" backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/. | 2 | 4 | Medium | 2017-01-18 | 2014-03-05 | View | |
41718 | CVE-2013-6839 | SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and earlier allows remote attackers to execute arbitrary SQL commands via the orderby parameter to catalog/[id]. | 2 | 7.5 | High | 2017-01-18 | 2013-12-16 | View | |
41974 | CVE-2013-7234 | Simple Machines Forum (SMF) before 1.1.19 and 2.x before 2.0.6 allows remote attackers to conduct clickjacking attacks via an X-Frame-Options header. | 2 | 4.3 | Medium | 2017-01-18 | 2014-04-30 | View | |
42230 | CVE-2012-0087 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.0.x and 5.1.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0101 and CVE-2012-0102. | 2 | 4 | Medium | 2017-01-19 | 2014-02-20 | View |
Page 17044 of 17672, showing 5 records out of 88360 total, starting on record 85216, ending on 85220