Vulnerabilities (CVE)

Filtered by CWE-200
Total 11056 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-5453 1 Ibm 1 Security Appscan 2026-06-16 3.5 LOW N/A
IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily predicted.
CVE-2013-5452 1 Ibm 1 Filenet Business Process Framework 2026-06-16 3.5 LOW N/A
IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
CVE-2013-5440 1 Ibm 1 Infosphere Information Server 2026-06-16 2.1 LOW N/A
IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 allows local users to obtain sensitive information in opportunistic circumstances by leveraging the presence of file content after a failed installation.
CVE-2013-5423 1 Ibm 1 Flex System Manager 2026-06-16 5.0 MEDIUM N/A
IBM Flex System Manager (FSM) 1.1 through 1.3 before 1.3.2.0 allows remote attackers to enumerate user accounts via unspecified vectors.
CVE-2013-5422 1 Ibm 1 Rational Clearcase 2026-06-16 4.3 MEDIUM N/A
The Web Client in IBM Rational ClearQuest 7.1 through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2, when a multi-database dataset exists, allows remote attackers to read database names via unspecified vectors.
CVE-2013-5380 1 Ibm 1 Maximo Asset Management 2026-06-16 2.1 LOW N/A
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors.
CVE-2013-5209 1 Freebsd 1 Freebsd 2026-06-16 7.8 HIGH N/A
The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does not properly initialize the state-cookie data structure, which allows remote attackers to obtain sensitive information from kernel stack memory by reading packet data in INIT-ACK chunks.
CVE-2013-5183 1 Apple 1 Mac Os X 2026-06-16 2.6 LOW N/A
Mail in Apple Mac OS X before 10.9, when Kerberos authentication is enabled and TLS is disabled, sends invalid cleartext data, which allows remote attackers to obtain sensitive information by sniffing the network.
CVE-2013-5150 1 Apple 1 Iphone Os 2026-06-16 1.9 LOW N/A
The history-clearing feature in Safari in Apple iOS before 7 does not clear the back/forward history of an open tab, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation.
CVE-2013-5142 1 Apple 1 Iphone Os 2026-06-16 4.9 MEDIUM N/A
The kernel in Apple iOS before 7 does not initialize unspecified kernel data structures, which allows local users to obtain sensitive information from kernel stack memory via the (1) msgctl API or (2) segctl API.
CVE-2013-5136 1 Apple 1 Apple Remote Desktop 2026-06-16 4.3 MEDIUM N/A
Apple Remote Desktop before 3.7 does not properly use server authentication-type information during decisions about whether to present an unencrypted-connection warning message, which allows remote attackers to obtain sensitive information in opportunistic circumstances by sniffing the network during an unintended cleartext VNC session.
CVE-2013-5130 1 Apple 1 Safari 2026-06-16 5.0 MEDIUM N/A
WebKit in Apple Safari before 6.1 disables the Private Browsing feature upon a launch of the Web Inspector, which makes it easier for context-dependent attackers to obtain browsing information by leveraging LocalStorage/ files.
CVE-2013-5054 1 Microsoft 2 Office, Office 2013 Rt 2026-06-16 4.3 MEDIUM N/A
Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."
CVE-2013-5008 1 Symantec 1 Management Platform 2026-06-16 4.6 MEDIUM N/A
The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers' installations, which makes it easier for local users to obtain sensitive information about package-server access, or cause a denial of service, by leveraging knowledge of this key.
CVE-2013-5000 1 Phpmyadmin 1 Phpmyadmin 2026-06-16 5.0 MEDIUM N/A
phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files.
CVE-2013-4999 1 Phpmyadmin 1 Phpmyadmin 2026-06-16 5.0 MEDIUM N/A
phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php.
CVE-2013-4998 1 Phpmyadmin 1 Phpmyadmin 2026-06-16 5.0 MEDIUM N/A
phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files.
CVE-2013-4961 1 Puppet 1 Puppet Enterprise 2026-06-16 5.0 MEDIUM N/A
Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information.
CVE-2013-4959 1 Puppet 1 Puppet Enterprise 2026-06-16 2.1 LOW N/A
Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host name, (2) MAC address, and (3) SSH keys via the web browser cache.
CVE-2013-4868 1 Karotz 1 Api 2026-06-16 5.0 MEDIUM 5.3 MEDIUM
Karotz API 12.07.19.00: Session Token Information Disclosure