|
283751
|
- |
|
wordpress
|
wordpress
|
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) at…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5739
|
2024-11-21 10:58 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283752
|
- |
|
wordpress
|
wordpress
|
The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it eas…
|
CWE-20
Improper Input Validation
|
CVE-2013-5738
|
2024-11-21 10:58 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283753
|
- |
|
gomlab
|
gom_player
|
Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.
|
CWE-20
Improper Input Validation
|
CVE-2013-5716
|
2024-11-21 10:58 |
2013-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283754
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2013-5594
|
2024-11-21 10:57 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283755
|
7.5 |
HIGH
Network
|
aicorporation
|
risknet_acquirer
|
RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
|
CWE-200
Information Exposure
|
CVE-2013-5687
|
2024-11-21 10:57 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283756
|
6.1 |
MEDIUM
Network
|
easyxdm
|
easyxdm
|
Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via the easyxdm.swf file.
|
CWE-79
Cross-site Scripting
|
CVE-2013-5212
|
2024-11-21 10:57 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283757
|
8.8 |
HIGH
Network
|
python-mode_project
|
python-mode
|
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
|
CWE-20
Improper Input Validation
|
CVE-2013-5106
|
2024-11-21 10:57 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283758
|
7.8 |
HIGH
Local
|
ammyy
|
ammyy_admin
|
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that ext…
|
CWE-287
Improper Authentication
|
CVE-2013-5582
|
2024-11-21 10:57 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283759
|
7.1 |
HIGH
Local
|
evernote
|
evernote
|
Evernote prior to 5.5.1 has insecure password change
|
CWE-287
Improper Authentication
|
CVE-2013-5116
|
2024-11-21 10:57 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283760
|
6.1 |
MEDIUM
Physics
|
logmein
|
lastpass
|
LastPass prior to 2.5.1 allows secure wipe bypass.
|
CWE-287
Improper Authentication
|
CVE-2013-5114
|
2024-11-21 10:57 |
2020-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|