|
283191
|
- |
|
devscripts_devel_team
|
devscripts
|
The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a direc…
|
CWE-94
Code Injection
|
CVE-2013-7050
|
2024-11-21 11:00 |
2013-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283192
|
- |
|
juniper
|
screenos netscreen-5200 netscreen-5400
|
Juniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote attackers to cause a denial of service via a crafted packet.
|
NVD-CWE-noinfo
|
CVE-2013-6958
|
2024-11-21 11:00 |
2013-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283193
|
- |
|
juniper
|
idp250 idp8200 idp800 idp75
|
Cross-site scripting (XSS) vulnerability in the web administrative component in Juniper IDP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the ACM web serve…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6957
|
2024-11-21 11:00 |
2013-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283194
|
- |
|
juniper
|
ive_os
|
Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r17, 7.3 before 7.3r8, 7.4…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6956
|
2024-11-21 11:00 |
2013-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283195
|
- |
|
cisco
|
unified_communications_manager
|
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discove…
|
CWE-310
Cryptographic Issues
|
CVE-2013-7030
|
2024-11-21 11:00 |
2013-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283196
|
- |
|
zippyyum
|
subway_ordering_for_california
|
The ZippyYum Subway CA Kiosk app 3.4 for iOS uses cleartext storage in SQLite cache databases, which allows attackers to obtain sensitive information by reading data elements, as demonstrated by pass…
|
CWE-310
Cryptographic Issues
|
CVE-2013-6986
|
2024-11-21 11:00 |
2013-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283197
|
- |
|
cisco
|
scientific_atlanta__dpr\/epr2320_firmware scientific_atlanta__dpr\/epr2320 scientific_atlanta__dpr2325_firmware scientific_atlanta__dpr2325
|
Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote attackers to hijack the authentication of adminis…
|
CWE-352
Origin Validation Error
|
CVE-2013-7043
|
2024-11-21 11:00 |
2013-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283198
|
- |
|
novell
|
suse_lifecycle_management_server
|
SUSE Lifecycle Management Server (SLMS) before 1.3.7 uses world-readable permissions for the secret keys, which allows local users to gain privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7042
|
2024-11-21 11:00 |
2013-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283199
|
- |
|
linux
|
linux_kernel
|
The ieee80211_radiotap_iterator_init function in net/wireless/radiotap.c in the Linux kernel before 3.11.7 does not check whether a frame contains any data outside of the header, which might allow at…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-7027
|
2024-11-21 11:00 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283200
|
- |
|
linux
|
linux_kernel
|
Multiple race conditions in ipc/shm.c in the Linux kernel before 3.12.2 allow local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via …
|
CWE-362
Race Condition
|
CVE-2013-7026
|
2024-11-21 11:00 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|