|
283701
|
- |
|
mozilla fedoraproject oracle canonical redhat suse opensuse
|
firefox seamonkey fedora solaris ubuntu_linux enterprise_linux_server enterprise_linux_server_eus enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_…
|
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attacker…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2013-5614
|
2024-11-21 10:57 |
2013-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283702
|
9.8 |
CRITICAL
Network
|
mozilla fedoraproject opensuse suse redhat canonical
|
firefox_esr firefox thunderbird seamonkey fedora opensuse suse_linux_enterprise_software_development_kit suse_linux_enterprise_desktop suse_linux_enterprise_server enterpri…
|
Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows …
|
CWE-416
Use After Free
|
CVE-2013-5613
|
2024-11-21 10:57 |
2013-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283703
|
- |
|
mozilla fedoraproject oracle canonical redhat suse opensuse
|
firefox seamonkey fedora solaris ubuntu_linux enterprise_linux_server enterprise_linux_server_eus enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_…
|
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Orig…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5612
|
2024-11-21 10:57 |
2013-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283704
|
9.8 |
CRITICAL
Network
|
mozilla fedoraproject opensuse suse canonical redhat
|
firefox_esr firefox thunderbird seamonkey fedora opensuse suse_linux_enterprise_software_development_kit suse_linux_enterprise_desktop suse_linux_enterprise_server ubuntu_l…
|
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to c…
|
NVD-CWE-noinfo
|
CVE-2013-5609
|
2024-11-21 10:57 |
2013-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283705
|
- |
|
adobe
|
flash_player air air_sdk
|
Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380…
|
CWE-94
Code Injection
|
CVE-2013-5331
|
2024-11-21 10:57 |
2013-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283706
|
- |
|
ibm
|
rational_requirements_composer rational_quality_manager rational_team_concert
|
Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational T…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5404
|
2024-11-21 10:57 |
2013-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283707
|
- |
|
ibm
|
forms_viewer
|
Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary code via an XFDL form with a long fontname value.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5447
|
2024-11-21 10:57 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283708
|
- |
|
sharetronix
|
sharetronix
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Sharetronix 3.1.1 allow remote attackers to hijack the authentication of administrators for requests that (1) change configuration settin…
|
CWE-352
Origin Validation Error
|
CVE-2013-5355
|
2024-11-21 10:57 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283709
|
- |
|
sharetronix
|
sharetronix
|
Multiple SQL injection vulnerabilities in Sharetronix 3.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) fb_user_id or (2) tw_user_id parameter to signup.
|
CWE-89
SQL Injection
|
CVE-2013-5354
|
2024-11-21 10:57 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283710
|
- |
|
ibm
|
smartcloud_provisioning
|
IBM SmartCloud Provisioning 2.1 before FP3 IF0001 allows remote authenticated users to modify virtual-system deployment via deployer.virtualsystems CLI commands, as demonstrated by a deletion using a…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5455
|
2024-11-21 10:57 |
2013-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|