NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
39958 | CVE-2013-4339 | WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string. | 2 | 7.5 | High | 2017-01-18 | 2013-12-30 | View | |
40214 | CVE-2013-4651 | Siemens Scalance W7xx devices with firmware before 4.5.4 use the same hardcoded X.509 certificate across different customers" installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate"s trust relationship. | 2 | 6.6 | Medium | 2017-01-18 | 2013-08-01 | View | |
40470 | CVE-2013-5000 | phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files. | 2 | 5 | Medium | 2017-01-18 | 2013-07-31 | View | |
40726 | CVE-2013-5428 | IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a denial of service via unspecified vectors. | 2 | 7.1 | High | 2017-01-18 | 2013-10-22 | View | |
40982 | CVE-2013-5750 | The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation. | 2 | 5 | Medium | 2017-01-18 | 2013-10-15 | View |
Page 1542 of 17672, showing 5 records out of 88360 total, starting on record 7706, ending on 7710