NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40708 | CVE-2013-5407 | IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue. | 2 | 4.9 | Medium | 2017-01-18 | 2013-12-23 | View | |
40964 | CVE-2013-5718 | The dissect_nbap_T_dCH_ID function in epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not restrict the dch_id value, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | 2 | 4.3 | Medium | 2017-01-18 | 2013-12-30 | View | |
41220 | CVE-2013-6017 | Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML via the body of an e-mail message, as demonstrated by the SRC attribute of an IFRAME element. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-30 | View | |
41476 | CVE-2013-6418 | PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate. | 2 | 5.8 | Medium | 2017-01-18 | 2016-11-28 | View | |
41732 | CVE-2013-6868 | SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows local users to obtain sensitive information via unspecified vectors. | 2 | 7.8 | High | 2017-01-18 | 2013-11-25 | View |
Page 672 of 17672, showing 5 records out of 88360 total, starting on record 3356, ending on 3360