NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40476 | CVE-2013-5008 | The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers" installations, which makes it easier for local users to obtain sensitive information about package-server access, or cause a denial of service, by leveraging knowledge of this key. | 2 | 4.6 | Medium | 2017-01-18 | 2013-10-10 | View | |
41244 | CVE-2013-6043 | The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests. | 2 | 5 | Medium | 2017-01-18 | 2015-01-08 | View | |
41500 | CVE-2013-6444 | PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-18 | 2016-11-28 | View | |
41756 | CVE-2013-6904 | Cross-site scripting (XSS) vulnerability in a note component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-18 | 2013-12-13 | View | |
42012 | CVE-2013-7279 | Cross-site scripting (XSS) vulnerability in views/video-management/preview_video.php in the S3 Video plugin before 0.983 for WordPress allows remote attackers to inject arbitrary web script or HTML via the base parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View |
Page 1035 of 17672, showing 5 records out of 88360 total, starting on record 5171, ending on 5175