NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40726 | CVE-2013-5428 | IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a denial of service via unspecified vectors. | 2 | 7.1 | High | 2017-01-18 | 2013-10-22 | View | |
40982 | CVE-2013-5750 | The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation. | 2 | 5 | Medium | 2017-01-18 | 2013-10-15 | View | |
41238 | CVE-2013-6037 | Cross-site scripting (XSS) vulnerability in index.php in Aker Secure Mail Gateway 2.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg_id parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View | |
41494 | CVE-2013-6438 | The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request. | 2 | 5 | Medium | 2017-01-18 | 2017-01-06 | View | |
41750 | CVE-2013-6891 | lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf. | 2 | 1.2 | Low | 2017-01-18 | 2014-03-05 | View |
Page 1359 of 17672, showing 5 records out of 88360 total, starting on record 6791, ending on 6795