NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40462 | CVE-2013-4986 | Stack-based buffer overflow in PDFAX0722_IconCool.dll 7.22.1125.2121 in IconCool PDFCool Studio 3.32 Build 130330 and earlier allows remote attackers to execute arbitrary code via a crafted PDF file. | 2 | 6.8 | Medium | 2017-01-18 | 2013-10-07 | View | |
40718 | CVE-2013-5420 | The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request. | 2 | 3.5 | Low | 2017-01-18 | 2013-12-24 | View | |
40974 | CVE-2013-5738 | The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file. | 2 | 4.3 | Medium | 2017-01-18 | 2013-09-26 | View | |
41230 | CVE-2013-6028 | Multiple cross-site request forgery (CSRF) vulnerabilities in Atmail Webmail Server before 7.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts, (2) modify user accounts, (3) delete user accounts, or (4) stop the product"s service. | 2 | 6.8 | Medium | 2017-01-18 | 2015-08-07 | View | |
41486 | CVE-2013-6429 | The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315. | 2 | 6.8 | Medium | 2017-01-18 | 2016-11-28 | View |
Page 1351 of 17672, showing 5 records out of 88360 total, starting on record 6751, ending on 6755