NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
38339  CVE-2013-2254  The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root node, which allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.    Medium  2017-01-18  2013-10-18  View
39363  CVE-2013-3596  AdvancePro Advanceware allows remote authenticated users to obtain sensitive information about arbitrary customers" orders via a modified id parameter.    Medium  2017-01-18  2013-09-11  View
39619  CVE-2013-3903  Array index error in win32k.sys in the kernel-mode drivers in Microsoft Windows 8, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to cause a denial of service (reboot) via a crafted TrueType font (TTF) file, aka "TrueType Font Parsing Vulnerability."    4.7  Medium  2017-01-18  2013-12-11  View
40643  CVE-2013-5313  Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/update.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to hijack the authentication of administrators for requests that modify arbitrary user accounts via an edit user action.    6.8  Medium  2017-01-18  2013-08-20  View
41155  CVE-2013-5935  The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 does not properly restrict the set of network interfaces that can receive API calls, which makes it easier for remote attackers to obtain access by sending network traffic from an unintended location, a different vulnerability than CVE-2013-5200.    4.3  Medium  2017-01-18  2013-09-25  View

Page 15534 of 17672, showing 5 records out of 88360 total, starting on record 77666, ending on 77670

Actions