|
283001
|
- |
|
entity_api_project
|
entity_api
|
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7391
|
2024-11-21 11:00 |
2014-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283002
|
- |
|
dlink
|
dir-645_firmware dir-645
|
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceid …
|
CWE-79
Cross-site Scripting
|
CVE-2013-7389
|
2024-11-21 11:00 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283003
|
- |
|
google trimble
|
sketchup
|
Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a crafted RLE4-compressed…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-7388
|
2024-11-21 11:00 |
2014-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283004
|
- |
|
vinay_sajip
|
python-gnupg
|
python-gnupg before 0.3.5 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
|
NVD-CWE-Other
|
CVE-2013-7323
|
2024-11-21 11:00 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283005
|
- |
|
dleviet
|
datalife_engine
|
Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID cookie.
|
NVD-CWE-Other
|
CVE-2013-7387
|
2024-11-21 11:00 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283006
|
- |
|
rom_walton
|
boinc
|
Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2.33, allows remote attackers to cause a denial of service (crash) or possibly ex…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2013-7386
|
2024-11-21 11:00 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283007
|
- |
|
x2go
|
x2go_server
|
x2gocleansessions in X2Go Server before 4.0.0.8 and 4.0.1.x before 4.0.1.10 allows remote authenticated users to gain privileges via unspecified vectors, possibly related to backticks.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7383
|
2024-11-21 11:00 |
2014-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283008
|
- |
|
cisco
|
nx-os
|
Directory traversal vulnerability in the command-line interface in Cisco NX-OS 6.2(2a) and earlier allows local users to read arbitrary files via unspecified input, aka Bug ID CSCul05217.
|
CWE-22
Path Traversal
|
CVE-2013-6975
|
2024-11-21 11:00 |
2014-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283009
|
- |
|
livezilla
|
livezilla
|
LiveZilla 5.1.2.1 and earlier includes the MD5 hash of the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which allows remote attackers to obtain sensitive…
|
CWE-310
Cryptographic Issues
|
CVE-2013-7385
|
2024-11-21 11:00 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283010
|
- |
|
unrealircd
|
unrealircd
|
UnrealIRCd 3.2.10 before 3.2.10.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via unspecified vectors, related to SSL. NOTE: this issue was SPLIT from C…
|
NVD-CWE-Other
|
CVE-2013-7384
|
2024-11-21 11:00 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|