NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
37657  CVE-2013-1464  Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.    4.3  Medium  2017-01-18  2016-12-07  View
37913  CVE-2013-1762  stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.    6.6  Medium  2017-01-18  2014-01-17  View
38169  CVE-2013-2055  Unspecified vulnerability in Apache Wicket 1.4.x before 1.4.23, 1.5.x before 1.5.11, and 6.x before 6.8.0 allows remote attackers to obtain sensitive information via vectors that cause raw HTML templates to be rendered without being processed and reading the information that is outside of wicket:panel markup.    Medium  2017-01-18  2014-02-11  View
38425  CVE-2013-2362  Unspecified vulnerability in HP System Management Homepage (SMH) before 7.2.1 allows local users to cause a denial of service via unknown vectors, aka ZDI-CAN-1676.    2.1  Low  2017-01-18  2013-07-22  View
38681  CVE-2013-2744  importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.    Medium  2017-01-18  2013-04-02  View

Page 2094 of 17672, showing 5 records out of 88360 total, starting on record 10466, ending on 10470

Actions