NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
41238 | CVE-2013-6037 | Cross-site scripting (XSS) vulnerability in index.php in Aker Secure Mail Gateway 2.5.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the msg_id parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View | |
41494 | CVE-2013-6438 | The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request. | 2 | 5 | Medium | 2017-01-18 | 2017-01-06 | View | |
41750 | CVE-2013-6891 | lppasswd in CUPS before 1.7.1, when running with setuid privileges, allows local users to read portions of arbitrary files via a modified HOME environment variable and a symlink attack involving .cups/client.conf. | 2 | 1.2 | Low | 2017-01-18 | 2014-03-05 | View | |
42006 | CVE-2013-7273 | GNOME Display Manager (gdm) 3.4.1 and earlier, when disable-user-list is set to true, allows local users to cause a denial of service (unable to login) by pressing the cancel button after entering a user name. | 2 | 2.1 | Low | 2017-01-18 | 2014-04-30 | View | |
42262 | CVE-2012-0119 | Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.x and 5.5.x allows remote authenticated users to affect availability via unknown vectors, a different vulnerability than CVE-2012-0112, CVE-2012-0115, CVE-2012-0120, CVE-2012-0485, and CVE-2012-0492. | 2 | 4 | Medium | 2017-01-19 | 2014-02-20 | View |
Page 1543 of 17672, showing 5 records out of 88360 total, starting on record 7711, ending on 7715