NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
41223 | CVE-2013-6020 | passwordRequestPOST.jsp in Tyler Technologies TaxWeb 3.13.3.1 sends different HTTP status codes for invalid password-recovery requests depending on whether the user account exists, which allows remote attackers to enumerate account names via a series of requests to the (1) Assessor, (2) Recorder, or (3) Treasurer application. | 2 | 5.8 | Medium | 2017-01-18 | 2013-11-21 | View | |
41479 | CVE-2013-6421 | The unpack_zip function in archive_unpacker.rb in the sprout gem 0.7.246 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a (1) filename or (2) path. | 2 | 7.5 | High | 2017-01-18 | 2013-12-19 | View | |
41735 | CVE-2013-6872 | SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a projectpdf action. | 2 | 6.5 | Medium | 2017-01-18 | 2015-07-28 | View | |
41991 | CVE-2013-7256 | Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | 2 | 6.8 | Medium | 2017-01-18 | 2014-02-24 | View | |
42247 | CVE-2012-0104 | Unspecified vulnerability in Oracle GlassFish Enterprise Server 3.0.1 and 3.1.1 allows remote attackers to affect availability via unknown vectors related to Web Container. | 2 | 5 | Medium | 2017-01-19 | 2012-01-30 | View |
Page 462 of 17672, showing 5 records out of 88360 total, starting on record 2306, ending on 2310