NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
38908 | CVE-2013-3032 | Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN986NAA. | 2 | 4.3 | Medium | 2017-01-18 | 2013-08-15 | View | |
39676 | CVE-2013-3981 | The Meeting Server in IBM Sametime 8.x through 8.5.2.1 and 9.x through 9.0.0.1 allows remote attackers to download avatar photos of arbitrary users via unspecified vectors. | 2 | 5 | Medium | 2017-01-18 | 2014-06-26 | View | |
39932 | CVE-2013-4306 | Cross-site request forgery (CSRF) vulnerability in api/ApiQueryCheckUser.php in the CheckUser extension for MediaWiki, possibly Checkuser before 2.3, allows remote attackers to hijack the authentication of arbitrary users for requests that "perform sensitive write actions" via unspecified vectors. | 2 | 6.8 | Medium | 2017-01-18 | 2013-10-15 | View | |
40444 | CVE-2013-4961 | Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information. | 2 | 5 | Medium | 2017-01-18 | 2013-10-07 | View | |
40956 | CVE-2013-5708 | Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via vectors related to cookies, a different vulnerability than CVE-2013-3605. | 2 | 6.8 | Medium | 2017-01-18 | 2013-09-06 | View |
Page 17558 of 17672, showing 5 records out of 88360 total, starting on record 87786, ending on 87790