NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
39418  CVE-2013-3661  The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.    4.9  Medium  2017-01-18  2013-06-05  View
40186  CVE-2013-4609  REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.    6.5  Medium  2017-01-18  2013-06-17  View
40442  CVE-2013-4958  Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended workstation.    6.9  Medium  2017-01-18  2013-10-07  View
40954  CVE-2013-5706  Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser"s HTML implementation, a different issue than CVE-2013-3603.    4.3  Medium  2017-01-18  2013-09-06  View
41210  CVE-2013-6005  Cross-site scripting (XSS) vulnerability in Cybozu Dezie before 8.1.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Cancel button.    4.3  Medium  2017-01-18  2013-12-16  View

Page 17489 of 17672, showing 5 records out of 88360 total, starting on record 87441, ending on 87445

Actions