|
283091
|
- |
|
belkin
|
wemo_home_automation_firmware
|
The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6949
|
2024-11-21 11:00 |
2014-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283092
|
- |
|
belkin
|
wemo_home_automation_firmware
|
The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunct…
|
CWE-94
Code Injection
|
CVE-2013-6948
|
2024-11-21 11:00 |
2014-02-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283093
|
- |
|
php
|
php
|
Multiple integer signedness errors in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allow remote attackers to cause a denial of service (application crash) or obtain sensitive inf…
|
CWE-189
Numeric Errors
|
CVE-2013-7328
|
2024-11-21 11:00 |
2014-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283094
|
- |
|
canonical php
|
ubuntu_linux php
|
The gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 does not check return values, which allows remote attackers to cause a denial of service (application crash) or possibly have unspeci…
|
CWE-20
Improper Input Validation
|
CVE-2013-7327
|
2024-11-21 11:00 |
2014-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283095
|
- |
|
php
|
php
|
Integer overflow in the gdImageCrop function in ext/gd/gd.c in PHP 5.5.x before 5.5.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impac…
|
CWE-189
Numeric Errors
|
CVE-2013-7226
|
2024-11-21 11:00 |
2014-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283096
|
- |
|
vtiger
|
vtiger_crm
|
Cross-site scripting (XSS) vulnerability in vTiger CRM 5.4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) return_url parameter to modules\com_vtiger_workflow\savetemplat…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7326
|
2024-11-21 11:00 |
2014-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283097
|
- |
|
livezilla
|
livezilla
|
Multiple cross-site scripting (XSS) vulnerabilities in the web based operator client in LiveZilla before 5.1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) name of an u…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7032
|
2024-11-21 11:00 |
2014-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283098
|
- |
|
openstack
|
compute havana grizzly icehouse
|
The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not prope…
|
CWE-200
Information Exposure
|
CVE-2013-7130
|
2024-11-21 11:00 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283099
|
- |
|
d-link
|
dap_2253_firmware dap_2253
|
Cross-site scripting (XSS) vulnerability in D-Link DAP-2253 Access Point (Rev. A1) with firmware before 1.30 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7321
|
2024-11-21 11:00 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283100
|
- |
|
d-link
|
dap_2253_firmware dap_2253
|
Cross-site request forgery (CSRF) vulnerability in D-Link DAP-2253 Access Point (Rev. A1) with firmware before 1.30 allows remote attackers to hijack the authentication of administrators for requests…
|
CWE-352
Origin Validation Error
|
CVE-2013-7320
|
2024-11-21 11:00 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|