NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 39921 | CVE-2013-4294 | The (1) mamcache and (2) KVS token backends in OpenStack Identity (Keystone) Folsom 2012.2.x and Grizzly before 2013.1.4 do not properly compare the PKI token revocation list with PKI tokens, which allow remote attackers to bypass intended access restrictions via a revoked PKI token. | 2 | 5 | Medium | 2017-01-18 | 2013-10-30 | View | |
| 40177 | CVE-2013-4594 | The Payment for Webform module 7.x-1.x before 7.x-1.5 for Drupal does not restrict access by anonymous users, which allows remote anonymous users to use the payment of other anonymous users when submitting a form that requires payment. | 2 | 4.3 | Medium | 2017-01-18 | 2014-10-30 | View | |
| 40433 | CVE-2013-4949 | Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in the upload form"s directory in data/. | 2 | 6.8 | Medium | 2017-01-18 | 2013-07-30 | View | |
| 40689 | CVE-2013-5382 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5383. | 2 | 4 | Medium | 2017-01-18 | 2013-10-10 | View | |
| 40945 | CVE-2013-5696 | inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action. | 2 | 6.8 | Medium | 2017-01-18 | 2013-09-23 | View |
Page 14605 of 17672, showing 5 records out of 88360 total, starting on record 73021, ending on 73025