|
286201
|
- |
|
glpi-project
|
glpi
|
inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to front/ticket.form.php.
|
NVD-CWE-Other
|
CVE-2013-2225
|
2024-11-21 10:51 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286202
|
- |
|
openbsd
|
opensmtpd
|
OpenSMTPD before 5.3.2 does not properly handle SSL sessions, which allows remote attackers to cause a denial of service (connection blocking) by keeping a connection open.
|
CWE-310
Cryptographic Issues
|
CVE-2013-2125
|
2024-11-21 10:51 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286203
|
- |
|
libguestfs
|
libguestfs
|
Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.
|
NVD-CWE-Other
|
CVE-2013-2124
|
2024-11-21 10:51 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286204
|
- |
|
dovecot
|
dovecot
|
The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid APPEND parameters.
|
CWE-20
Improper Input Validation
|
CVE-2013-2111
|
2024-11-21 10:51 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286205
|
- |
|
uplawski
|
creme_fraiche
|
The set_meta_data function in lib/cremefraiche.rb in the Creme Fraiche gem before 0.6.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the file name of an …
|
CWE-78
OS Command
|
CVE-2013-2090
|
2024-11-21 10:51 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286206
|
- |
|
mail_on_update_project
|
mail_on_update
|
Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change…
|
CWE-352
Origin Validation Error
|
CVE-2013-2107
|
2024-11-21 10:51 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286207
|
- |
|
glpi-project
|
glpi
|
Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) fi…
|
CWE-89
SQL Injection
|
CVE-2013-2226
|
2024-11-21 10:51 |
2014-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286208
|
- |
|
galleryproject
|
gallery
|
Multiple cross-site scripting (XSS) vulnerabilities in Gallery 3 before 3.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) movie title to modules/gallery/controllers/movi…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2087
|
2024-11-21 10:51 |
2014-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286209
|
- |
|
apache
|
archiva
|
Cross-site scripting (XSS) vulnerability in Apache Archiva 1.2 through 1.2.2 and 1.3 before 1.3.8 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, related to…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2187
|
2024-11-21 10:51 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286210
|
- |
|
jonathan_leung
|
show_in_browser
|
The Show In Browser (show_in_browser) gem 0.0.3 for Ruby allows local users to inject arbitrary web script or HTML via a symlink attack on /tmp/browser.html.
|
CWE-59
Link Following
|
CVE-2013-2105
|
2024-11-21 10:51 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|