|
282991
|
9.8 |
CRITICAL
Network
|
clamav debian fedoraproject
|
clamav debian_linux fedora
|
ClamAV before 0.97.7 has buffer overflow in the libclamav component
|
CWE-120
Classic Buffer Overflow
|
CVE-2013-7088
|
2024-11-21 11:00 |
2019-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282992
|
9.8 |
CRITICAL
Network
|
clamav debian fedoraproject
|
clamav debian_linux fedora
|
ClamAV before 0.97.7 has WWPack corrupt heap memory
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-7087
|
2024-11-21 11:00 |
2019-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282993
|
7.5 |
HIGH
Network
|
projectfloodlight
|
open_sdn_controller
|
A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to selectively disconnect individual switches from t…
|
CWE-20
Improper Input Validation
|
CVE-2013-7333
|
2024-11-21 11:00 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282994
|
9.8 |
CRITICAL
Network
|
xstream_project
|
xstream
|
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed inpu…
|
CWE-78
OS Command
|
CVE-2013-7285
|
2024-11-21 11:00 |
2019-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282995
|
5.5 |
MEDIUM
Local
|
gitolite
|
gitolite
|
gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.
|
CWE-200
Information Exposure
|
CVE-2013-7203
|
2024-11-21 11:00 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282996
|
8.1 |
HIGH
Network
|
paypal
|
paypal
|
The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7202
|
2024-11-21 11:00 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282997
|
7.4 |
HIGH
Network
|
paypal
|
paypal
|
WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
|
CWE-295
Improper Certificate Validation
|
CVE-2013-7201
|
2024-11-21 11:00 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282998
|
7.5 |
HIGH
Network
|
sybase
|
adaptive_server_enterprise
|
The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate credentials, aka SAP …
|
CWE-285
Improper Authorization
|
CVE-2013-7245
|
2024-11-21 11:00 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282999
|
6.5 |
MEDIUM
Network
|
evergreen-ils
|
evergreen
|
The open-ils.pcrud endpoint in Evergreen before 2.5.9, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to obtain sensitive settings history information by leveraging lack of user p…
|
CWE-200
Information Exposure
|
CVE-2013-7435
|
2024-11-21 11:00 |
2018-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283000
|
7.5 |
HIGH
Network
|
dkd
|
direct_mail
|
The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication codes.
|
CWE-200
Information Exposure
|
CVE-2013-7400
|
2024-11-21 11:00 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|