|
288131
|
- |
|
apache
|
cxf
|
Apache CXF before 2.5.9, 2.6.x before 2.6.6, and 2.7.x before 2.7.3, when the plaintext UsernameToken WS-SecurityPolicy is enabled, allows remote attackers to bypass authentication via a security hea…
|
CWE-287
Improper Authentication
|
CVE-2013-0239
|
2024-11-21 10:47 |
2013-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288132
|
- |
|
boost
|
boost
|
boost::locale::utf::utf_traits in the Boost.Locale library in Boost 1.48 through 1.52 does not properly detect certain invalid UTF-8 sequences, which might allow remote attackers to bypass input vali…
|
CWE-20
Improper Input Validation
|
CVE-2013-0252
|
2024-11-21 10:47 |
2013-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288133
|
- |
|
haxx canonical
|
libcurl curl ubuntu_linux
|
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows r…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-0249
|
2024-11-21 10:47 |
2013-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288134
|
- |
|
git-scm
|
git
|
The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which al…
|
CWE-20
Improper Input Validation
|
CVE-2013-0308
|
2024-11-21 10:47 |
2013-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288135
|
- |
|
openstack
|
essex folsom
|
manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to…
|
CWE-362
Race Condition
|
CVE-2013-0266
|
2024-11-21 10:47 |
2013-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288136
|
- |
|
openstack
|
essex folsom
|
(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0261
|
2024-11-21 10:47 |
2013-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288137
|
- |
|
oracle
|
javafx jdk jre
|
Heap-based buffer overflow in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-0402
|
2024-11-21 10:47 |
2013-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288138
|
- |
|
oracle
|
jdk jre
|
The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to execute…
|
CWE-94
Code Injection
|
CVE-2013-0401
|
2024-11-21 10:47 |
2013-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288139
|
- |
|
xen
|
xen
|
oxenstored in Xen 4.1.x, Xen 4.2.x, and xen-unstable does not properly consider the state of the Xenstore ring during read operations, which allows guest OS users to cause a denial of service (daemon…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0215
|
2024-11-21 10:47 |
2013-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288140
|
- |
|
hp redhat
|
linux_imaging_and_printing_project enterprise_linux
|
HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/h…
|
CWE-59
Link Following
|
CVE-2013-0200
|
2024-11-21 10:47 |
2013-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|