NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40444 | CVE-2013-4961 | Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information. | 2 | 5 | Medium | 2017-01-18 | 2013-10-07 | View | |
40700 | CVE-2013-5398 | Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5397. | 2 | 3.3 | Low | 2017-01-18 | 2013-12-18 | View | |
40956 | CVE-2013-5708 | Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via vectors related to cookies, a different vulnerability than CVE-2013-3605. | 2 | 6.8 | Medium | 2017-01-18 | 2013-09-06 | View | |
41212 | CVE-2013-6009 | CRLF injection vulnerability in Open-Xchange AppSuite before 7.2.2, when using AJP in certain conditions, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the ajax/defer servlet. | 2 | 4.3 | Medium | 2017-01-18 | 2013-10-04 | View | |
41468 | CVE-2013-6410 | nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file. | 2 | 7.5 | High | 2017-01-18 | 2016-11-28 | View |
Page 17451 of 17672, showing 5 records out of 88360 total, starting on record 87251, ending on 87255