NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
40278  CVE-2013-4732  ** DISPUTED ** The administrative web server on the Digital Alert Systems DASDEC EAS device through 2.0-2 and the Monroe Electronics R189 One-Net EAS device through 2.0-2 uses predictable session ID values, which makes it easier for remote attackers to hijack sessions by sniffing the network. NOTE: VU#662676 states "Monroe Electronics could not reproduce this finding."    10  High  2017-01-18  2013-07-01  View
40534  CVE-2013-5117  SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.    7.5  High  2017-01-18  2014-03-13  View
41302  CVE-2013-6172  steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.    7.5  High  2017-01-18  2014-03-26  View
42326  CVE-2012-0187  Untrusted search path vulnerability in IBM Lotus Expeditor 6.1.x and 6.2.x before 6.2 FP5+Security Pack allows local users to gain privileges via a Trojan horse DLL in the current working directory.    9.3  High  2017-01-19  2012-06-22  View
42838  CVE-2012-0759  Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.    10  High  2017-01-19  2012-02-16  View

Page 2644 of 17672, showing 5 records out of 88360 total, starting on record 13216, ending on 13220

Actions