NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
39684 | CVE-2013-3990 | Cross-site scripting (XSS) vulnerability in the MIME e-mail functionality in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN98FLQ2. | 2 | 4.3 | Medium | 2017-01-18 | 2013-08-13 | View | |
39940 | CVE-2013-4315 | Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_ROOTS setting followed by a .. (dot dot) in a ssi template tag. | 2 | 5 | Medium | 2017-01-18 | 2013-12-10 | View | |
40196 | CVE-2013-4620 | Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the note parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2013-08-13 | View | |
40452 | CVE-2013-4971 | Puppet Enterprise before 3.2.0 does not properly restrict access to node endpoints in the console, which allows remote attackers to obtain sensitive information via unspecified vectors. | 2 | 5 | Medium | 2017-01-18 | 2014-03-10 | View | |
40708 | CVE-2013-5407 | IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue. | 2 | 4.9 | Medium | 2017-01-18 | 2013-12-23 | View |
Page 176 of 17672, showing 5 records out of 88360 total, starting on record 876, ending on 880