NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
38885 | CVE-2013-2993 | IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.7 does not properly perform authentication for unspecified web services, which allows remote attackers to issue requests in the context of an arbitrary user"s active session via unknown vectors. | 2 | 5.8 | Medium | 2017-01-18 | 2013-08-01 | View | |
39397 | CVE-2013-3640 | Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 12 and Pro Advanced before 12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-18 | 2013-06-11 | View | |
39909 | CVE-2013-4282 | Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket. | 2 | 5 | Medium | 2017-01-18 | 2017-01-02 | View | |
41189 | CVE-2013-5977 | Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers to hijack the authentication of administrators for requests that (1) create or modify products or conduct cross-site scripting (XSS) attacks via the (2) Product name or (3) Price description field in a product save action via a request to wp-admin/admin.php. | 2 | 6.8 | Medium | 2017-01-18 | 2013-11-20 | View | |
41445 | CVE-2013-6386 | Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass intended restrictions via a brute force attack. | 2 | 6.8 | Medium | 2017-01-18 | 2014-01-13 | View |
Page 16743 of 17672, showing 5 records out of 88360 total, starting on record 83711, ending on 83715