NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
39932 | CVE-2013-4306 | Cross-site request forgery (CSRF) vulnerability in api/ApiQueryCheckUser.php in the CheckUser extension for MediaWiki, possibly Checkuser before 2.3, allows remote attackers to hijack the authentication of arbitrary users for requests that "perform sensitive write actions" via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-18 | 2013-10-15 | View | |
40188 | CVE-2013-4611 | Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Online Designer page or (2) the Manage Survey Participants page. | 2 | 10 | High | 2017-01-18 | 2013-06-17 | View | |
40444 | CVE-2013-4961 | Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information. | 2 | 5 | Medium | 2017-01-18 | 2013-10-07 | View | |
40700 | CVE-2013-5398 | Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5397. | 2 | 3.3 | Low | 2017-01-18 | 2013-12-18 | View | |
40956 | CVE-2013-5708 | Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via vectors related to cookies, a different vulnerability than CVE-2013-3605. | 2 | 6.8 | Medium | 2017-01-18 | 2013-09-06 | View |
Page 17474 of 17672, showing 5 records out of 88360 total, starting on record 87366, ending on 87370