NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40420 | CVE-2013-4936 | The IsDFP_Frame function in plugins/profinet/packet-pn-rt.c in the PROFINET Real-Time dissector in Wireshark 1.10.x before 1.10.1 does not validate MAC addresses, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted packet. | 2 | 5 | Medium | 2017-01-18 | 2015-12-14 | View | |
40676 | CVE-2013-5364 | Secunia CSI Agent 6.0.0.15017 and earlier, 6.0.1.1007 and earlier, and 7.0.0.21 and earlier, when running on Red Hat Linux, uses world-readable and world-writable permissions for /etc/csia_config.xml, which allows local users to change CSI Agent configuration by modifying this file. | 2 | 3.6 | Low | 2017-01-18 | 2014-01-27 | View | |
40932 | CVE-2013-5673 | SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to wp-admin/admin-ajax.php. | 2 | 7.5 | High | 2017-01-18 | 2013-09-11 | View | |
41188 | CVE-2013-5976 | Cross-site scripting (XSS) vulnerability in the access policy logout page (logout.inc) in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.1.0 through 11.3.0 allows remote attackers to inject arbitrary web script or HTML via the LastMRH_Session cookie. | 2 | 4.3 | Medium | 2017-01-18 | 2013-10-30 | View | |
41444 | CVE-2013-6385 | The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote attackers to trigger application-specific impacts such as arbitrary code execution via application-specific vectors. | 2 | 5.1 | Medium | 2017-01-18 | 2014-01-13 | View |
Page 16019 of 17672, showing 5 records out of 88360 total, starting on record 80091, ending on 80095