NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 38656 | CVE-2013-2716 | Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgrading from older 1.2.x or 2.0.x versions, which allows remote attackers to obtain console access via a crafted cookie. | 2 | 5 | Medium | 2017-01-18 | 2013-04-11 | View | |
| 38912 | CVE-2013-3036 | Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL. | 2 | 4.9 | Medium | 2017-01-18 | 2013-09-12 | View | |
| 39168 | CVE-2013-3360 | Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3359. | 2 | 10 | High | 2017-01-18 | 2013-09-12 | View | |
| 39424 | CVE-2013-3667 | The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates. | 2 | 6.4 | Medium | 2017-01-18 | 2014-01-03 | View | |
| 39680 | CVE-2013-3985 | The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 does not properly restrict application cookies, which allows remote attackers to read session variables by leveraging a weak setting of the Domain variable. | 2 | 2.9 | Low | 2017-01-18 | 2013-11-14 | View |
Page 2243 of 17672, showing 5 records out of 88360 total, starting on record 11211, ending on 11215