NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
38656  CVE-2013-2716  Puppet Labs Puppet Enterprise before 2.8.0 does not use a "randomized secret" in the CAS client config file (cas_client_config.yml) when upgrading from older 1.2.x or 2.0.x versions, which allows remote attackers to obtain console access via a crafted cookie.    Medium  2017-01-18  2013-04-11  View
38912  CVE-2013-3036  Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.    4.9  Medium  2017-01-18  2013-09-12  View
39168  CVE-2013-3360  Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3359.    10  High  2017-01-18  2013-09-12  View
39424  CVE-2013-3667  The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.    6.4  Medium  2017-01-18  2014-01-03  View
39680  CVE-2013-3985  The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 does not properly restrict application cookies, which allows remote attackers to read session variables by leveraging a weak setting of the Domain variable.    2.9  Low  2017-01-18  2013-11-14  View

Page 2243 of 17672, showing 5 records out of 88360 total, starting on record 11211, ending on 11215

Actions