|
287141
|
- |
|
rom_walton
|
boinc
|
Multiple stack-based buffer overflows in the XML parser in BOINC 7.x allow attackers to have unspecified impact via a crafted XML file, related to the scheduler.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-2298
|
2024-11-21 10:51 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287142
|
- |
|
apache
|
hbase
|
Apache HBase 0.92.x before 0.92.3 and 0.94.x before 0.94.9, when the Kerberos features are enabled, allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive inf…
|
CWE-287
Improper Authentication
|
CVE-2013-2193
|
2024-11-21 10:51 |
2014-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287143
|
- |
|
glpi-project
|
glpi
|
inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to front/ticket.form.php.
|
NVD-CWE-Other
|
CVE-2013-2225
|
2024-11-21 10:51 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287144
|
- |
|
openbsd
|
opensmtpd
|
OpenSMTPD before 5.3.2 does not properly handle SSL sessions, which allows remote attackers to cause a denial of service (connection blocking) by keeping a connection open.
|
CWE-310
Cryptographic Issues
|
CVE-2013-2125
|
2024-11-21 10:51 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287145
|
- |
|
libguestfs
|
libguestfs
|
Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.
|
NVD-CWE-Other
|
CVE-2013-2124
|
2024-11-21 10:51 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287146
|
- |
|
dovecot
|
dovecot
|
The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid APPEND parameters.
|
CWE-20
Improper Input Validation
|
CVE-2013-2111
|
2024-11-21 10:51 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287147
|
- |
|
uplawski
|
creme_fraiche
|
The set_meta_data function in lib/cremefraiche.rb in the Creme Fraiche gem before 0.6.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the file name of an …
|
CWE-78
OS Command
|
CVE-2013-2090
|
2024-11-21 10:51 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287148
|
- |
|
mail_on_update_project
|
mail_on_update
|
Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change…
|
CWE-352
Origin Validation Error
|
CVE-2013-2107
|
2024-11-21 10:51 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287149
|
- |
|
glpi-project
|
glpi
|
Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) fi…
|
CWE-89
SQL Injection
|
CVE-2013-2226
|
2024-11-21 10:51 |
2014-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287150
|
- |
|
galleryproject
|
gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movi…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2087
|
2024-11-21 10:51 |
2014-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|