NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40450 | CVE-2013-4967 | Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the password is "seeded as a console parameter," External Node Classifiers, and the lack of access control for /nodes. | 2 | 5 | Medium | 2017-01-18 | 2013-10-07 | View | |
40962 | CVE-2013-5716 | Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file. | 2 | 4.3 | Medium | 2017-01-18 | 2013-10-08 | View | |
41218 | CVE-2013-6015 | Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of service (flow daemon crash) via an unspecified sequence of TCP packets. | 2 | 4.3 | Medium | 2017-01-18 | 2016-10-06 | View | |
41474 | CVE-2013-6416 | Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View | |
42498 | CVE-2012-0389 | Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4.26 and earlier, 5.x before 5.53, and 6.x before 6.03 allows remote attackers to inject arbitrary web script or HTML via the Username parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2012-02-16 | View |
Page 102 of 17672, showing 5 records out of 88360 total, starting on record 506, ending on 510