NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
36601 | CVE-2013-0246 | The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of otherwise restricted images via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-18 | 2013-07-16 | View | |
36857 | CVE-2013-0532 | Cross-site request forgery (CSRF) vulnerability in IBM Security AppScan Enterprise 5.6 and 8.x before 8.7 and IBM Rational Policy Tester 5.6 and 8.x before 8.5.0.4 allows remote attackers to hijack the authentication of arbitrary users for requests that cause a denial of service via malformed HTTP data. | 2 | 6.8 | Medium | 2017-01-18 | 2013-03-29 | View | |
37625 | CVE-2013-1413 | Multiple cross-site scripting (XSS) vulnerabilities in synetics i-doit open 0.9.9-7, i-doit pro 1.0 and earlier, and i-doit pro 1.0.2 when the "sanitize user input" flag is not enabled, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-18 | 2014-02-12 | View | |
38137 | CVE-2013-2021 | pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file. | 2 | 4.3 | Medium | 2017-01-18 | 2015-09-28 | View | |
38649 | CVE-2013-2707 | Cross-site request forgery (CSRF) vulnerability in the Login With Ajax plugin before 3.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin"s settings. | 2 | 6.8 | Medium | 2017-01-18 | 2013-05-10 | View |
Page 17452 of 17672, showing 5 records out of 88360 total, starting on record 87256, ending on 87260