|
289731
|
5.5 |
MEDIUM
Local
|
canonical
|
remote-login-service
|
In crypt.c of remote-login-service, the cryptographic algorithm used to cache usernames and passwords is insecure. An attacker could use this vulnerability to recover usernames and passwords from the…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2013-1053
|
2024-11-21 10:48 |
2021-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289732
|
9.8 |
CRITICAL
Network
|
polarbear_cms_project
|
polarbear_cms
|
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2013-0803
|
2024-11-21 10:48 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289733
|
6.1 |
MEDIUM
Network
|
chamilo
|
chamilo
|
Chamilo 1.9.4 has XSS due to improper validation of user-supplied input by the chat.php script.
|
CWE-79
Cross-site Scripting
|
CVE-2013-0739
|
2024-11-21 10:48 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289734
|
6.1 |
MEDIUM
Network
|
chamilo
|
chamilo
|
Chamilo 1.9.4 has Multiple XSS and HTML Injection Vulnerabilities: blog.php and announcements.php.
|
CWE-79
Cross-site Scripting
|
CVE-2013-0738
|
2024-11-21 10:48 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289735
|
7.8 |
HIGH
Local
|
hexagongeospatial
|
erdas_er_viewer
|
ERDAS ER Viewer 13.0 has dwmapi.dll and irml.dll libraries arbitrary code execution vulnerabilities
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2013-0725
|
2024-11-21 10:48 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289736
|
6.1 |
MEDIUM
Network
|
boltwire
|
boltwire
|
Cross-site scripting (XSS) vulnerability in BoltWire 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the fieldnames parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-0737
|
2024-11-21 10:48 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289737
|
9.8 |
CRITICAL
Network
|
ffmpeg
|
ffmpeg
|
The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.
|
NVD-CWE-noinfo
|
CVE-2013-0870
|
2024-11-21 10:48 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289738
|
- |
|
canonical
|
ubuntu_linux
|
The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1068
|
2024-11-21 10:48 |
2014-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289739
|
- |
|
corel
|
paintshop_pro_x5 paintshop_pro_x6
|
Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan hors…
|
NVD-CWE-Other
|
CVE-2013-0733
|
2024-11-21 10:48 |
2014-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289740
|
- |
|
wpshopstyling
|
wp-ecommerce-shop-styling
|
PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote attackers to execute arbitrary PHP code via a URL i…
|
CWE-94
Code Injection
|
CVE-2013-0724
|
2024-11-21 10:48 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|