|
291221
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.
|
CWE-20
Improper Input Validation
|
CVE-2013-1689
|
2024-11-21 10:50 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291222
|
7.5 |
HIGH
Network
|
redhat
|
openstack openstack_essex
|
openstack-utils openstack-db has insecure password creation
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2013-1793
|
2024-11-21 10:50 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291223
|
7.5 |
HIGH
Network
|
mediawiki debian redhat fedoraproject
|
mediawiki debian_linux enterprise_linux fedora
|
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2013-1817
|
2024-11-21 10:50 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291224
|
7.5 |
HIGH
Network
|
mediawiki debian redhat fedoraproject
|
mediawiki debian_linux enterprise_linux fedora
|
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
|
CWE-20
Improper Input Validation
|
CVE-2013-1816
|
2024-11-21 10:50 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291225
|
7.5 |
HIGH
Network
|
mod_ruid2_project
|
mod_ruid2
|
mod_ruid2 before 0.9.8 improperly handles file descriptors which allows remote attackers to bypass security using a CGI script to break out of the chroot.
|
CWE-20
Improper Input Validation
|
CVE-2013-1889
|
2024-11-21 10:50 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291226
|
5.5 |
MEDIUM
Local
|
redhat fedoraproject
|
tuned fedora
|
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
|
CWE-20
Improper Input Validation
|
CVE-2013-1820
|
2024-11-21 10:50 |
2019-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291227
|
4.3 |
MEDIUM
Network
|
mantisbt debian
|
mantisbt debian_linux
|
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
|
CWE-20
Improper Input Validation
|
CVE-2013-1811
|
2024-11-21 10:50 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291228
|
7.5 |
HIGH
Network
|
gambas_project debian
|
gambas debian_linux
|
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.
|
CWE-59
Link Following
|
CVE-2013-1809
|
2024-11-21 10:50 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291229
|
7.5 |
HIGH
Network
|
monkey-project
|
monkey
|
The web server Monkeyd produces a world-readable log (/var/log/monkeyd/master.log) on gentoo.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2013-1771
|
2024-11-21 10:50 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291230
|
9.8 |
CRITICAL
Network
|
twiki
|
twiki
|
TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.
|
CWE-20
Improper Input Validation
|
CVE-2013-1751
|
2024-11-21 10:50 |
2019-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|