NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40975 | CVE-2013-5739 | The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php. | 2 | 3.5 | Low | 2017-01-18 | 2013-09-26 | View | |
41231 | CVE-2013-6029 | Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code via a malformed .SVT file. | 2 | 6.8 | Medium | 2017-01-18 | 2016-12-30 | View | |
41487 | CVE-2013-6431 | The fib6_add function in net/ipv6/ip6_fib.c in the Linux kernel before 3.11.5 does not properly implement error-code encoding, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for an IPv6 SIOCADDRT ioctl call. | 2 | 4.7 | Medium | 2017-01-18 | 2014-03-05 | View | |
41743 | CVE-2013-6884 | The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges. | 2 | 10 | High | 2017-01-18 | 2014-02-24 | View | |
41999 | CVE-2013-7265 | The pn_recvmsg function in net/phonet/datagram.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call. | 2 | 4.9 | Medium | 2017-01-18 | 2014-03-16 | View |
Page 940 of 17672, showing 5 records out of 88360 total, starting on record 4696, ending on 4700