NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
40726  CVE-2013-5428  IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a denial of service via unspecified vectors.    7.1  High  2017-01-18  2013-10-22  View
40982  CVE-2013-5750  The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation.    Medium  2017-01-18  2013-10-15  View
41238  CVE-2013-6037  Cross-site scripting (XSS) vulnerability in index.php in Aker Secure Mail Gateway 2.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg_id parameter.    4.3  Medium  2017-01-18  2016-12-30  View
41494  CVE-2013-6438  The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.    Medium  2017-01-18  2017-01-06  View
41750  CVE-2013-6891  lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf.    1.2  Low  2017-01-18  2014-03-05  View

Page 1359 of 17672, showing 5 records out of 88360 total, starting on record 6791, ending on 6795

Actions