NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
40218  CVE-2013-4661  CiviCRM 2.0.0 through 4.2.9 and 4.3.0 through 4.3.3 does not properly enforce role-based access control (RBAC) restrictions for default custom searches, which allows remote authenticated users with the "access CiviCRM" permission to bypass intended access restrictions, as demonstrated by accessing custom contribution data without having the "access CiviContribute" permission.    4.9  Medium  2017-01-18  2014-02-21  View
40474  CVE-2013-5005  Multiple cross-site scripting (XSS) vulnerabilities in ajaxRequest/methodCall.do in Tripwire Enterprise 8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) m_target_class_name, (2) m_target_method_name, or (3) m_request_context_params parameters.    4.3  Medium  2017-01-18  2016-12-30  View
40730  CVE-2013-5433  The Data Growth Solution for JD Edwards EnterpriseOne in IBM InfoSphere Optim 3.0 through 9.1 has hardcoded database credentials, which allows remote authenticated users to obtain sensitive information by reading an unspecified field in an XML document.    Medium  2017-01-18  2014-08-12  View
40986  CVE-2013-5756  Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to cgi-bin/cgiServer.exx.    Medium  2017-01-18  2014-08-04  View
41242  CVE-2013-6041  index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.    7.5  High  2017-01-18  2015-01-08  View

Page 2164 of 17672, showing 5 records out of 88360 total, starting on record 10816, ending on 10820

Actions