|
287891
|
7.5 |
HIGH
Network
|
redhat
|
mrg_management_console
|
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a syste…
|
CWE-295
Improper Certificate Validation
|
CVE-2013-0264
|
2024-11-21 10:47 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287892
|
6.5 |
MEDIUM
Network
|
redhat
|
openshift
|
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the …
|
CWE-352
Origin Validation Error
|
CVE-2013-0196
|
2024-11-21 10:47 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287893
|
6.1 |
MEDIUM
Network
|
owncloud
|
owncloud
|
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.
|
CWE-79
Cross-site Scripting
|
CVE-2013-0202
|
2024-11-21 10:47 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287894
|
7.8 |
HIGH
Local
|
ovirt
|
node
|
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
|
CWE-269
Improper Privilege Management
|
CVE-2013-0293
|
2024-11-21 10:47 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287895
|
4.3 |
MEDIUM
Network
|
pyrad_project
|
pyrad
|
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability tha…
|
CWE-20
Improper Input Validation
|
CVE-2013-0342
|
2024-11-21 10:47 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287896
|
5.5 |
MEDIUM
Local
|
openstack debian
|
nova debian_linux
|
OpenStack nova base images permissions are world readable
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2013-0326
|
2024-11-21 10:47 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287897
|
5.4 |
MEDIUM
Network
|
theforeman
|
katello
|
Katello: Username in Notification page has cross site scripting
|
CWE-79
Cross-site Scripting
|
CVE-2013-0283
|
2024-11-21 10:47 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287898
|
7.4 |
HIGH
Network
|
haskell
|
hs-tls
|
haskell-tls-extra before 0.6.1 has Basic Constraints attribute vulnerability may lead to Man in the Middle attacks on TLS connections
|
CWE-20
Improper Input Validation
|
CVE-2013-0243
|
2024-11-21 10:47 |
2019-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287899
|
5.4 |
MEDIUM
Network
|
owncloud
|
owncloud
|
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) unspecified parameters to apps/cal…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0203
|
2024-11-21 10:47 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287900
|
6.1 |
MEDIUM
Network
|
matomo
|
matomo
|
Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 an…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0195
|
2024-11-21 10:47 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|