NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
37871 | CVE-2013-1708 | Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (application crash) via a crafted WAV file that is not properly handled by the nsCString::CharAt function. | 2 | 4.3 | Medium | 2017-01-18 | 2013-11-02 | View | |
38127 | CVE-2013-2004 | The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file. | 2 | 6.8 | Medium | 2017-01-18 | 2013-06-20 | View | |
38639 | CVE-2013-2697 | Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences. | 2 | 6.8 | Medium | 2017-01-18 | 2013-04-22 | View | |
39407 | CVE-2013-3650 | Directory traversal vulnerability in the lfCheckFileName function in data/class/pages/LC_Page_ResizeImage.php in LOCKON EC-CUBE before 2.12.5 allows remote attackers to read arbitrary image files via vectors involving the image parameter to resize_image.php, a different vulnerability than CVE-2013-3654. | 2 | 5 | Medium | 2017-01-18 | 2013-10-11 | View | |
39663 | CVE-2013-3963 | Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models allows remote attackers to hijack the authentication of unspecified victims for requests that add users. | 2 | 6.8 | Medium | 2017-01-18 | 2013-10-02 | View |
Page 17079 of 17672, showing 5 records out of 88360 total, starting on record 85391, ending on 85395