NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40450 | CVE-2013-4967 | Puppet Enterprise before 3.0.1 allows remote attackers to obtain the database password via vectors related to how the password is "seeded as a console parameter," External Node Classifiers, and the lack of access control for /nodes. | 2 | 5 | Medium | 2017-01-18 | 2013-10-07 | View | |
40706 | CVE-2013-5405 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters. | 2 | 3.5 | Low | 2017-01-18 | 2016-12-30 | View | |
40962 | CVE-2013-5716 | Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file. | 2 | 4.3 | Medium | 2017-01-18 | 2013-10-08 | View | |
41218 | CVE-2013-6015 | Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of service (flow daemon crash) via an unspecified sequence of TCP packets. | 2 | 4.3 | Medium | 2017-01-18 | 2016-10-06 | View | |
41474 | CVE-2013-6416 | Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View |
Page 185 of 17672, showing 5 records out of 88360 total, starting on record 921, ending on 925