NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
41245 | CVE-2013-6044 | The is_safe_url function in utils/http.py in Django 1.4.x before 1.4.6, 1.5.x before 1.5.2, and 1.6 before beta 2 treats a URL"s scheme as safe even if it is not HTTP or HTTPS, which might introduce cross-site scripting (XSS) or other vulnerabilities into Django applications that use this function, as demonstrated by "the login view in django.contrib.auth.views" and the javascript: scheme. | 2 | 4.3 | Medium | 2017-01-18 | 2013-12-10 | View | |
41501 | CVE-2013-6445 | Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier for attackers to obtain sensitive information via a brute-force attack. | 2 | 5 | Medium | 2017-01-18 | 2014-07-18 | View | |
41757 | CVE-2013-6905 | Cross-site scripting (XSS) vulnerability in a phone component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-18 | 2013-12-13 | View | |
42013 | CVE-2013-7280 | Buffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of service (crash) via a long string in a .m3u file. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View | |
42269 | CVE-2012-0126 | Unspecified vulnerability in the WBEM implementation in HP HP-UX 11.11 and 11.23 allows remote attackers to obtain access to diagnostic information via unknown vectors, a related issue to CVE-2012-0125. | 2 | 5.8 | Medium | 2017-01-19 | 2012-06-27 | View |
Page 1785 of 17672, showing 5 records out of 88360 total, starting on record 8921, ending on 8925