NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
39365  CVE-2013-3598  Directory traversal vulnerability in servlet/CreateTemplateServlet in SearchBlox before 7.5 build 1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the name parameter.    Medium  2017-01-18  2013-09-10  View
39877  CVE-2013-4238  The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a "" character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.    4.3  Medium  2017-01-18  2014-12-11  View
40389  CVE-2013-4881  Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to hijack the authentication of administrators for requests that create an administrative user via an add user action to index.php.    6.8  Medium  2017-01-18  2013-10-07  View
41157  CVE-2013-5937  Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API.    6.8  Medium  2017-01-18  2013-10-23  View
41669  CVE-2013-6780  Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.    4.3  Medium  2017-01-18  2015-07-28  View

Page 15604 of 17672, showing 5 records out of 88360 total, starting on record 78016, ending on 78020

Actions