|
284751
|
- |
|
mediawiki
|
mediawiki
|
Multiple cross-site scripting (XSS) vulnerabilities in repo/includes/EntityView.php in the Wikibase extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow …
|
CWE-79
Cross-site Scripting
|
CVE-2013-4307
|
2024-11-21 10:55 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284752
|
- |
|
wordpress
|
wordpress
|
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4340
|
2024-11-21 10:55 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284753
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
|
CWE-20
Improper Input Validation
|
CVE-2013-4339
|
2024-11-21 10:55 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284754
|
- |
|
wordpress
|
wordpress
|
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP u…
|
CWE-94
Code Injection
|
CVE-2013-4338
|
2024-11-21 10:55 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284755
|
- |
|
imagemagick
|
imagemagick
|
The ReadGIFImage function in coders/gif.c in ImageMagick before 6.7.8-8 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted comment in a GIF i…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4298
|
2024-11-21 10:55 |
2013-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284756
|
- |
|
fedoraproject
|
389_directory_server
|
ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request.
|
CWE-20
Improper Input Validation
|
CVE-2013-4283
|
2024-11-21 10:55 |
2013-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284757
|
- |
|
libtiff debian
|
libtiff debian_linux
|
Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary c…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4243
|
2024-11-21 10:55 |
2013-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284758
|
- |
|
libtiff debian
|
libtiff debian_linux
|
Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary co…
|
CWE-399
Resource Management Errors
|
CVE-2013-4232
|
2024-11-21 10:55 |
2013-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284759
|
- |
|
gnome
|
gnome_display_manager
|
GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.
|
CWE-59
Link Following
|
CVE-2013-4169
|
2024-11-21 10:55 |
2013-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284760
|
- |
|
erikwebb
|
password_policy
|
Cross-site scripting (XSS) vulnerability in the password_policy_admin_view function in password_policy.admin.inc in the Password Policy module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Dr…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4274
|
2024-11-21 10:55 |
2013-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|