Total
11056 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2013-5453 | 1 Ibm | 1 Security Appscan | 2026-06-16 | 3.5 LOW | N/A |
| IBM Security AppScan Enterprise 5.6 through 8.7.0.1 allows remote authenticated users to read arbitrary report files by leveraging knowledge of filenames that cannot be easily predicted. | |||||
| CVE-2013-5452 | 1 Ibm | 1 Filenet Business Process Framework | 2026-06-16 | 3.5 LOW | N/A |
| IBM FileNet Business Process Framework 4.1.0 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |||||
| CVE-2013-5440 | 1 Ibm | 1 Infosphere Information Server | 2026-06-16 | 2.1 LOW | N/A |
| IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 allows local users to obtain sensitive information in opportunistic circumstances by leveraging the presence of file content after a failed installation. | |||||
| CVE-2013-5423 | 1 Ibm | 1 Flex System Manager | 2026-06-16 | 5.0 MEDIUM | N/A |
| IBM Flex System Manager (FSM) 1.1 through 1.3 before 1.3.2.0 allows remote attackers to enumerate user accounts via unspecified vectors. | |||||
| CVE-2013-5422 | 1 Ibm | 1 Rational Clearcase | 2026-06-16 | 4.3 MEDIUM | N/A |
| The Web Client in IBM Rational ClearQuest 7.1 through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2, when a multi-database dataset exists, allows remote attackers to read database names via unspecified vectors. | |||||
| CVE-2013-5380 | 1 Ibm | 1 Maximo Asset Management | 2026-06-16 | 2.1 LOW | N/A |
| IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors. | |||||
| CVE-2013-5209 | 1 Freebsd | 1 Freebsd | 2026-06-16 | 7.8 HIGH | N/A |
| The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does not properly initialize the state-cookie data structure, which allows remote attackers to obtain sensitive information from kernel stack memory by reading packet data in INIT-ACK chunks. | |||||
| CVE-2013-5183 | 1 Apple | 1 Mac Os X | 2026-06-16 | 2.6 LOW | N/A |
| Mail in Apple Mac OS X before 10.9, when Kerberos authentication is enabled and TLS is disabled, sends invalid cleartext data, which allows remote attackers to obtain sensitive information by sniffing the network. | |||||
| CVE-2013-5150 | 1 Apple | 1 Iphone Os | 2026-06-16 | 1.9 LOW | N/A |
| The history-clearing feature in Safari in Apple iOS before 7 does not clear the back/forward history of an open tab, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation. | |||||
| CVE-2013-5142 | 1 Apple | 1 Iphone Os | 2026-06-16 | 4.9 MEDIUM | N/A |
| The kernel in Apple iOS before 7 does not initialize unspecified kernel data structures, which allows local users to obtain sensitive information from kernel stack memory via the (1) msgctl API or (2) segctl API. | |||||
| CVE-2013-5136 | 1 Apple | 1 Apple Remote Desktop | 2026-06-16 | 4.3 MEDIUM | N/A |
| Apple Remote Desktop before 3.7 does not properly use server authentication-type information during decisions about whether to present an unencrypted-connection warning message, which allows remote attackers to obtain sensitive information in opportunistic circumstances by sniffing the network during an unintended cleartext VNC session. | |||||
| CVE-2013-5130 | 1 Apple | 1 Safari | 2026-06-16 | 5.0 MEDIUM | N/A |
| WebKit in Apple Safari before 6.1 disables the Private Browsing feature upon a launch of the Web Inspector, which makes it easier for context-dependent attackers to obtain browsing information by leveraging LocalStorage/ files. | |||||
| CVE-2013-5054 | 1 Microsoft | 2 Office, Office 2013 Rt | 2026-06-16 | 4.3 MEDIUM | N/A |
| Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability." | |||||
| CVE-2013-5008 | 1 Symantec | 1 Management Platform | 2026-06-16 | 4.6 MEDIUM | N/A |
| The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers' installations, which makes it easier for local users to obtain sensitive information about package-server access, or cause a denial of service, by leveraging knowledge of this key. | |||||
| CVE-2013-5000 | 1 Phpmyadmin | 1 Phpmyadmin | 2026-06-16 | 5.0 MEDIUM | N/A |
| phpMyAdmin 3.5.x before 3.5.8.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to config.default.php and other files. | |||||
| CVE-2013-4999 | 1 Phpmyadmin | 1 Phpmyadmin | 2026-06-16 | 5.0 MEDIUM | N/A |
| phpMyAdmin 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to Error.class.php and Error_Handler.class.php. | |||||
| CVE-2013-4998 | 1 Phpmyadmin | 1 Phpmyadmin | 2026-06-16 | 5.0 MEDIUM | N/A |
| phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files. | |||||
| CVE-2013-4961 | 1 Puppet | 1 Puppet Enterprise | 2026-06-16 | 5.0 MEDIUM | N/A |
| Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information. | |||||
| CVE-2013-4959 | 1 Puppet | 1 Puppet Enterprise | 2026-06-16 | 2.1 LOW | N/A |
| Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host name, (2) MAC address, and (3) SSH keys via the web browser cache. | |||||
| CVE-2013-4868 | 1 Karotz | 1 Api | 2026-06-16 | 5.0 MEDIUM | 5.3 MEDIUM |
| Karotz API 12.07.19.00: Session Token Information Disclosure | |||||
