NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40445 | CVE-2013-4962 | The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors. | 2 | 5.8 | Medium | 2017-01-18 | 2013-10-07 | View | |
40701 | CVE-2013-5400 | An unspecified servlet in IBM Platform Symphony Developer Edition (DE) 5.2 and 6.1.x through 6.1.1 has hardcoded credentials, which allows remote attackers to bypass authentication and obtain "local environment" access via unknown vectors. | 2 | 10 | High | 2017-01-18 | 2014-02-14 | View | |
40957 | CVE-2013-5709 | The authentication implementation in the web server on Siemens SCALANCE X-200 switches with firmware before 5.0.0 does not use a sufficient source of entropy for generating values of random numbers, which makes it easier for remote attackers to hijack sessions by predicting a value. | 2 | 8.3 | High | 2017-01-18 | 2013-09-17 | View | |
41213 | CVE-2013-6010 | Cross-site scripting (XSS) vulnerability in the Comment Attachment plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Attachment field title." | 2 | 4.3 | Medium | 2017-01-18 | 2013-10-04 | View | |
41469 | CVE-2013-6411 | The HandleCrashedAircraft function in aircraft_cmd.cpp in OpenTTD 0.3.6 through 1.3.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) by crashing an aircraft outside of the map. | 2 | 5 | Medium | 2017-01-18 | 2014-01-13 | View |
Page 17534 of 17672, showing 5 records out of 88360 total, starting on record 87666, ending on 87670