NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 37822 | CVE-2013-1651 | OXUpdater in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof update servers and install arbitrary software via a crafted certificate. | 2 | 5.8 | Medium | 2017-01-18 | 2014-03-05 | View | |
| 38078 | CVE-2013-1953 | Integer underflow in the input_bmp_reader function in input-bmp.c in AutoTrace 0.31.1 allows context-dependent attackers to have an unspecified impact via a small value in the biSize field in the header of a BMP file, which triggers a buffer overflow. | 2 | 6.8 | Medium | 2017-01-18 | 2013-12-13 | View | |
| 38590 | CVE-2013-2585 | Cross-site scripting (XSS) vulnerability in Atmail Webmail Server 6.6.x before 6.6.3 and 7.0.x before 7.0.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php/mail/viewmessage/getattachment/folder/INBOX/uniqueId/<MessageID>/filenameOriginal/. | 2 | 4.3 | Medium | 2017-01-18 | 2014-02-13 | View | |
| 39102 | CVE-2013-3269 | Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0 allows remote attackers to hijack the authentication of arbitrary users for requests that change mobile passwords, a different vulnerability than CVE-2013-2305. | 2 | 6.8 | Medium | 2017-01-18 | 2013-05-03 | View | |
| 39358 | CVE-2013-3589 | Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2013-09-25 | View |
Page 15357 of 17672, showing 5 records out of 88360 total, starting on record 76781, ending on 76785