|
283011
|
- |
|
apple python
|
mac_os_x python
|
Python 2.7 before 3.4 only uses the last eight bits of the prefix to randomize hash values, which causes it to compute hash values without restricting the ability to trigger hash collisions predictab…
|
CWE-310
Cryptographic Issues
|
CVE-2013-7040
|
2024-11-21 11:00 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283012
|
- |
|
livezilla
|
livezilla
|
LiveZilla before 5.1.2.1 includes the operator password in plaintext in Javascript code that is generated by lz/mobile/chat.php, which might allow remote attackers to obtain sensitive information and…
|
CWE-310
Cryptographic Issues
|
CVE-2013-7033
|
2024-11-21 11:00 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283013
|
- |
|
opentext
|
exceed_ondemand
|
OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.
|
CWE-310
Cryptographic Issues
|
CVE-2013-6994
|
2024-11-21 11:00 |
2014-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283014
|
- |
|
vicidial
|
vicidial
|
VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users, which makes it easier for remote attackers to o…
|
CWE-255
Credentials Management
|
CVE-2013-7382
|
2024-11-21 11:00 |
2014-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283015
|
- |
|
ucdok
|
tomato
|
The admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a string, which allows remote attackers to bypass authentication via a string in t…
|
CWE-287
Improper Authentication
|
CVE-2013-7379
|
2024-11-21 11:00 |
2014-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283016
|
- |
|
openx
|
openx
|
Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to hijack the authentication of administrators, as demonstrated by r…
|
CWE-352
Origin Validation Error
|
CVE-2013-7376
|
2024-11-21 11:00 |
2014-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283017
|
- |
|
cristian_gafton
|
pam_userdb
|
The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.
|
CWE-310
Cryptographic Issues
|
CVE-2013-7041
|
2024-11-21 11:00 |
2014-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283018
|
- |
|
redhat opensuse
|
libvirt opensuse
|
The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a…
|
NVD-CWE-Other
|
CVE-2013-7336
|
2024-11-21 11:00 |
2014-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283019
|
- |
|
libpng
|
libpng
|
Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of service (crash) via a crafted image to the (1) png_set_sPLT or (2) png_set_text_2 function, which tr…
|
CWE-189
Numeric Errors
|
CVE-2013-7354
|
2024-11-21 11:00 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283020
|
- |
|
libpng
|
libpng
|
Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14beta08 allows context-dependent attackers to cause a denial of service (segmentation fault and crash)…
|
CWE-189
Numeric Errors
|
CVE-2013-7353
|
2024-11-21 11:00 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|