Latest CVE Feed
-
5.4
MEDIUM- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-5594
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding... Read more
Affected Products : firefox- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-5582
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.... Read more
Affected Products : ammyy_admin- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2013-5571
HMailServer 5.3.x and prior: Memory Corruption which could cause DOS... Read more
Affected Products : hmailserver- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-5461
IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.... Read more
- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2013-5391
IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.0 Fix Pack 2 make it easier for attackers to defea... Read more
- Published: Apr. 27, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-5212
Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via the easyxdm.swf file.... Read more
Affected Products : easyxdm- Published: Feb. 14, 2020
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2013-5123
The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.... Read more
- Published: Nov. 05, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-5122
Cisco Linksys Routers EA2700, EA3500, E4200, EA4500: A bug can cause an unsafe TCP port to open which leads to unauthenticated access... Read more
- Published: Jan. 07, 2020
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2013-5116
Evernote prior to 5.5.1 has insecure password change... Read more
Affected Products : evernote- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
6.6
MEDIUMCVE-2013-5114
LastPass prior to 2.5.1 allows secure wipe bypass.... Read more
Affected Products : lastpass- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2013-5113
LastPass prior to 2.5.1 has an insecure PIN implementation.... Read more
Affected Products : lastpass- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
4.6
MEDIUMCVE-2013-5112
Evernote before 5.5.1 has insecure PIN storage... Read more
Affected Products : evernote- Published: Jan. 31, 2020
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-5106
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.... Read more
Affected Products : python-mode- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-5027
Collabtive 1.0 has incorrect access control... Read more
Affected Products : collabtive- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4985
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream... Read more
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4982
AVTECH AVN801 DVR has a security bypass via the administration login captcha... Read more
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4976
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials... Read more
- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
9.0
HIGH- Published: Dec. 27, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4968
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."... Read more
Affected Products : puppet_enterprise- Published: Dec. 11, 2019
- Modified: Nov. 21, 2024