NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
38358  CVE-2013-2290  Cross-site scripting (XSS) vulnerability in the dashboard of the ArubaOS Administration WebUI in Aruba Networks ArubaOS 6.2.x before 6.2.0.3, 6.1.3.x before 6.1.3.7, 6.1.x-FIPS before 6.1.4.3-FIPS, and 6.1.x-AirGroup before 6.1.3.6-AirGroup, as used by Mobility Controller, allows remote wireless access points to inject arbitrary web script or HTML via a crafted SSID.    4.3  Medium  2017-01-18  2013-03-29  View
38614  CVE-2013-2635  The rtnl_fill_ifinfo function in net/core/rtnetlink.c in the Linux kernel before 3.8.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.    1.9  Low  2017-01-18  2014-02-06  View
38870  CVE-2013-2974  The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration privileges, and consequently create or delete reports or conduct SQL injection attacks, via crafted parameters to the BIRT reporting URL.    7.5  High  2017-01-18  2014-01-29  View
39126  CVE-2013-3300  The JsonParser class in json/JsonParser.scala in Lift before 2.5 interprets a certain end-index value as a length value, which allows remote authenticated users to obtain sensitive information from other users" sessions via invalid input data containing a < (less than) character.    Medium  2017-01-18  2013-07-29  View
39382  CVE-2013-3615  Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack.    7.8  High  2017-01-18  2013-09-17  View

Page 14510 of 17672, showing 5 records out of 88360 total, starting on record 72546, ending on 72550

Actions