|
291251
|
- |
|
mozilla canonical oracle redhat
|
network_security_services ubuntu_linux glassfish_server iplanet_web_proxy_server traffic_director iplanet_web_server vm_server glassfish_communications_server enterprise_manag…
|
The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC p…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2013-1620
|
2024-11-21 10:50 |
2013-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291252
|
- |
|
gnu
|
gnutls
|
The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the pr…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1619
|
2024-11-21 10:50 |
2013-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291253
|
- |
|
opera
|
opera_browser
|
The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which allows remote attack…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1618
|
2024-11-21 10:50 |
2013-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291254
|
- |
|
opera
|
opera_browser
|
Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism via a crafted web site that triggers a CORS request.
|
CWE-352
Origin Validation Error
|
CVE-2013-1639
|
2024-11-21 10:50 |
2013-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291255
|
- |
|
opera
|
opera_browser
|
Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.
|
CWE-94
Code Injection
|
CVE-2013-1638
|
2024-11-21 10:50 |
2013-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291256
|
- |
|
opera
|
opera_browser
|
Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events.
|
CWE-94
Code Injection
|
CVE-2013-1637
|
2024-11-21 10:50 |
2013-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291257
|
9.8 |
CRITICAL
Network
|
cardozatechnologies
|
wordpress_poll
|
Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and del…
|
CWE-89
SQL Injection
|
CVE-2013-1401
|
2024-11-21 10:49 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291258
|
9.8 |
CRITICAL
Network
|
cardozatechnologies
|
wordpress_poll
|
Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollRes…
|
CWE-89
SQL Injection
|
CVE-2013-1400
|
2024-11-21 10:49 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291259
|
6.1 |
MEDIUM
Network
|
perforce
|
p4web
|
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
|
CWE-79
Cross-site Scripting
|
CVE-2013-1410
|
2024-11-21 10:49 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291260
|
9.8 |
CRITICAL
Network
|
pdfkit_project
|
pdfkit
|
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability
|
CWE-20
Improper Input Validation
|
CVE-2013-1607
|
2024-11-21 10:49 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|