|
288541
|
- |
|
parallels
|
parallels_plesk_panel
|
The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing cr…
|
CWE-94
Code Injection
|
CVE-2013-0132
|
2024-11-21 10:46 |
2013-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288542
|
- |
|
microsoft
|
windows_defender
|
The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users to gain privileges via a crafted application, aka…
|
CWE-20
Improper Input Validation
|
CVE-2013-0078
|
2024-11-21 10:46 |
2013-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288543
|
- |
|
airdroid
|
airdroid
|
Cross-site scripting (XSS) vulnerability in the web interface in AirDroid allows remote attackers to inject arbitrary web script or HTML via a crafted text message that is transmitted by a managed ph…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0134
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288544
|
- |
|
nvidia
|
gpu_driver
|
Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout mode is enabled, allows remote authenticated users…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-0131
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288545
|
- |
|
nvidia
|
driver
|
daemonu.exe (aka the NVIDIA Update Service Daemon), as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service pa…
|
NVD-CWE-Other
|
CVE-2013-0111
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288546
|
- |
|
nvidia
|
driver
|
nvSCPAPISvr.exe in the NVIDIA Stereoscopic 3D Driver service, as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the …
|
NVD-CWE-Other
|
CVE-2013-0110
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288547
|
- |
|
chatelao
|
php_address_book
|
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) address…
|
CWE-89
SQL Injection
|
CVE-2013-0135
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288548
|
- |
|
nvidia
|
display_driver
|
The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, which allows local users to gain privileges or cau…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-0109
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288549
|
- |
|
tigertext
|
tigertext
|
The Contact Customer Support feature in the TigerText Free Private Texting app before 3.1.402 for iOS sends a log-file e-mail message with unencrypted credentials, which allows remote attackers to ob…
|
CWE-255
Credentials Management
|
CVE-2013-0128
|
2024-11-21 10:46 |
2013-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288550
|
- |
|
c2enterprise
|
c2_webresource
|
Cross-site scripting (XSS) vulnerability in fileview.asp in C2 WebResource allows remote attackers to inject arbitrary web script or HTML via the File parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-0125
|
2024-11-21 10:46 |
2013-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|