NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
39930 | CVE-2013-4304 | The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password. | 2 | 7.5 | High | 2017-01-18 | 2014-01-27 | View | |
40186 | CVE-2013-4609 | REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call. | 2 | 6.5 | Medium | 2017-01-18 | 2013-06-17 | View | |
40442 | CVE-2013-4958 | Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended workstation. | 2 | 6.9 | Medium | 2017-01-18 | 2013-10-07 | View | |
40698 | CVE-2013-5395 | IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to bypass intended access restrictions via unspecified vectors. | 2 | 7.5 | High | 2017-01-18 | 2013-10-10 | View | |
40954 | CVE-2013-5706 | Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser"s HTML implementation, a different issue than CVE-2013-3603. | 2 | 4.3 | Medium | 2017-01-18 | 2013-09-06 | View |
Page 16964 of 17672, showing 5 records out of 88360 total, starting on record 84816, ending on 84820