|
286111
|
- |
|
lester_chan
|
wp-downloadmanager
|
Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that in…
|
CWE-352
Origin Validation Error
|
CVE-2013-2697
|
2024-11-21 10:52 |
2013-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286112
|
- |
|
google
|
chrome_os
|
Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechan…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2835
|
2024-11-21 10:52 |
2013-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286113
|
- |
|
google
|
chrome_os
|
Google Chrome OS before 26.0.1410.57 does not properly enforce origin restrictions for the O3D and Google Talk plug-ins, which allows remote attackers to bypass the domain-whitelist protection mechan…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2834
|
2024-11-21 10:52 |
2013-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286114
|
- |
|
google
|
chrome_os
|
Use-after-free vulnerability in the O3D plug-in in Google Chrome OS before 26.0.1410.57 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors rela…
|
CWE-399
Resource Management Errors
|
CVE-2013-2833
|
2024-11-21 10:52 |
2013-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286115
|
- |
|
google
|
chrome_os
|
The Buffer::Set function in core/cross/buffer.cc in the O3D plug-in in Google Chrome OS before 26.0.1410.57 does not prevent uninitialized data from remaining in a buffer, which might allow remote at…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-2832
|
2024-11-21 10:52 |
2013-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286116
|
- |
|
bestwebsharing
|
groovy_media_player
|
Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-2760
|
2024-11-21 10:52 |
2013-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286117
|
- |
|
qualcomm motorola
|
msm8960 android atrix_hd razr_hd razr_m
|
The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the …
|
CWE-16
Configuration
|
CVE-2013-3051
|
2024-11-21 10:52 |
2013-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286118
|
- |
|
zapms
|
zapms
|
SQL injection vulnerability in ZAPms 1.41 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter to product.
|
CWE-89
SQL Injection
|
CVE-2013-3050
|
2024-11-21 10:52 |
2013-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286119
|
- |
|
cisco
|
ios_xe asr_1001 asr_1002 asr_1002-x asr_1002_fixed_router asr_1004 asr_1006 asr_1013 asr_1023_router
|
Cisco IOS XE 3.4 before 3.4.5S, and 3.5 through 3.7 before 3.7.1S, on 1000 series Aggregation Services Routers (ASR) does not properly implement the Cisco Multicast Leaf Recycle Elimination (MLRE) fe…
|
CWE-20
Improper Input Validation
|
CVE-2013-2779
|
2024-11-21 10:52 |
2013-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286120
|
- |
|
splunk
|
splunk
|
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 4.3.0 through 4.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2766
|
2024-11-21 10:52 |
2013-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|