NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
39673 | CVE-2013-3978 | The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 does not send the appropriate HTTP response headers to prevent unwanted caching by a web browser, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation. | 2 | 5 | Medium | 2017-01-18 | 2014-02-18 | View | |
39929 | CVE-2013-4302 | (1) ApiBlock.php, (2) ApiCreateAccount.php, (3) ApiLogin.php, (4) ApiMain.php, (5) ApiQueryDeletedrevs.php, (6) ApiTokens.php, and (7) ApiUnblock.php in includes/api/ in MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow remote attackers to obtain CSRF tokens and bypass the cross-site request forgery (CSRF) protection mechanism via a JSONP request to wiki/api.php. | 2 | 5 | Medium | 2017-01-18 | 2013-12-08 | View | |
40185 | CVE-2013-4608 | Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View & Descriptive Stats page. | 2 | 4.3 | Medium | 2017-01-18 | 2013-06-17 | View | |
40441 | CVE-2013-4957 | The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted report-specific type. | 2 | 6.8 | Medium | 2017-01-18 | 2013-10-28 | View | |
40697 | CVE-2013-5394 | The monitoring console in IBM WebSphere eXtreme Scale 7.1.0, 7.1.1, 8.5.0, and 8.6.0 allows remote authenticated users to conduct phishing attacks via unspecified vectors. | 2 | 4.9 | Medium | 2017-01-18 | 2013-10-16 | View |
Page 17292 of 17672, showing 5 records out of 88360 total, starting on record 86456, ending on 86460