NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40440 | CVE-2013-4956 | Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, installs modules with weak permissions if those permissions were used when the modules were originally built, which might allow local users to read or modify those modules depending on the original permissions. | 2 | 3.6 | Low | 2017-01-18 | 2013-10-07 | View | |
40696 | CVE-2013-5393 | The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors. | 2 | 7.5 | High | 2017-01-18 | 2013-10-16 | View | |
40952 | CVE-2013-5704 | The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such." | 2 | 5 | Medium | 2017-01-18 | 2017-01-06 | View | |
41208 | CVE-2013-6003 | CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers via unspecified vectors. | 2 | 3.5 | Low | 2017-01-18 | 2014-01-03 | View | |
41720 | CVE-2013-6852 | Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication of administrators for requests that change an administrative password via the setPassword method. | 2 | 6.8 | Medium | 2017-01-18 | 2013-11-22 | View |
Page 17232 of 17672, showing 5 records out of 88360 total, starting on record 86156, ending on 86160