|
287301
|
- |
|
mozilla
|
bugzilla
|
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allows remote attackers…
|
CWE-352
Origin Validation Error
|
CVE-2013-1734
|
2024-11-21 10:50 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287302
|
- |
|
mozilla
|
bugzilla
|
Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that modify bugs…
|
CWE-352
Origin Validation Error
|
CVE-2013-1733
|
2024-11-21 10:50 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287303
|
- |
|
mozilla
|
network_security_services
|
Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possib…
|
NVD-CWE-noinfo
|
CVE-2013-1739
|
2024-11-21 10:50 |
2013-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287304
|
- |
|
gnome
|
librsvg
|
GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML Ext…
|
CWE-20
Improper Input Validation
|
CVE-2013-1881
|
2024-11-21 10:50 |
2013-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287305
|
- |
|
openstack
|
python-keystoneclient
|
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the pro…
|
CWE-200
Information Exposure
|
CVE-2013-2013
|
2024-11-21 10:50 |
2013-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287306
|
- |
|
mongodb redhat
|
mongodb enterprise_mrg
|
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (inv…
|
CWE-20
Improper Input Validation
|
CVE-2013-1892
|
2024-11-21 10:50 |
2013-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287307
|
- |
|
squid-cache
|
squid
|
The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a ",…
|
CWE-20
Improper Input Validation
|
CVE-2013-1839
|
2024-11-21 10:50 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287308
|
- |
|
redhat
|
cloudforms_management_engine
|
Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a .. (dot dot) in th…
|
CWE-22
Path Traversal
|
CVE-2013-2068
|
2024-11-21 10:50 |
2013-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287309
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.
|
CWE-310
Cryptographic Issues
|
CVE-2013-1921
|
2024-11-21 10:50 |
2013-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287310
|
- |
|
mozilla
|
seamonkey thunderbird firefox
|
Use-after-free vulnerability in the JS_GetGlobalForScopeChain function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary …
|
CWE-399
Resource Management Errors
|
CVE-2013-1738
|
2024-11-21 10:50 |
2013-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|