|
291581
|
- |
|
openstack
|
swift
|
The OpenStack Python client library for Swift (python-swiftclient) 1.0 through 1.9.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and…
|
CWE-310
Cryptographic Issues
|
CVE-2013-6396
|
2024-11-21 10:59 |
2014-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291582
|
- |
|
mozilla
|
seamonkey thunderbird thunderbird_esr
|
Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6674
|
2024-11-21 10:59 |
2014-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291583
|
- |
|
ryan_ohara
|
piranha
|
The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an H…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6492
|
2024-11-21 10:59 |
2014-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291584
|
- |
|
linuxcontainers
|
lxc
|
The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6441
|
2024-11-21 10:59 |
2014-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291585
|
- |
|
shibboleth internet2
|
opensaml
|
The (1) BasicParserPool, (2) StaticBasicParserPool, (3) XML Decrypter, and (4) SAML Decrypter in Shibboleth OpenSAML-Java before 2.6.1 set the expandEntityReferences property to true, which allows re…
|
CWE-200
Information Exposure
|
CVE-2013-6440
|
2024-11-21 10:59 |
2014-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291586
|
- |
|
ibm
|
sametime
|
Cross-site scripting (XSS) vulnerability in the Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 allows remote authenticated users to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6743
|
2024-11-21 10:59 |
2014-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291587
|
- |
|
ibm
|
sametime
|
The Meeting Server in IBM Sametime 8.5.2 through 8.5.2.1 and 9.x through 9.0.0.1 do not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6742
|
2024-11-21 10:59 |
2014-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291588
|
- |
|
ibm
|
websphere_portal
|
Unrestricted file upload vulnerability in the Registration/Edit My Profile portlet in IBM WebSphere Portal 7.x before 7.0.0.2 CF27 and 8.x through 8.0.0.1 CF09 allows remote attackers to cause a deni…
|
NVD-CWE-Other
|
CVE-2013-6722
|
2024-11-21 10:59 |
2014-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291589
|
- |
|
ibm
|
websphere_dashboard_framework
|
The charting component in IBM WebSphere Dashboard Framework (WDF) 6.1.5 and 7.0.1 allows remote attackers to view or delete image files by leveraging incorrect security constraints for a temporary di…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6728
|
2024-11-21 10:59 |
2014-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291590
|
- |
|
ibm
|
algo_one
|
Unrestricted file upload vulnerability in IBM Algo One UDS 4.7.0 through 5.0.0 allows remote authenticated users to execute arbitrary code by uploading a .jsp file and then launching it.
|
NVD-CWE-Other
|
CVE-2013-6332
|
2024-11-21 10:59 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|