|
286291
|
- |
|
apple todd_miller
|
mac_os_x sudo
|
sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2777
|
2024-11-21 10:52 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286292
|
- |
|
todd_miller apple
|
sudo mac_os_x
|
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling ter…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2776
|
2024-11-21 10:52 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286293
|
- |
|
novell
|
kanaka
|
The installation functionality in the Novell Kanaka component before 2.8 for Novell Open Enterprise Server (OES) on Mac OS X does not verify the server's X.509 certificate during an SSL session, whic…
|
CWE-20
Improper Input Validation
|
CVE-2013-2770
|
2024-11-21 10:52 |
2013-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286294
|
- |
|
schneider-electric
|
magelis_xbt_hmi
|
The Schneider Electric Magelis XBT HMI controller has a default password for authentication of configuration uploads, which makes it easier for remote attackers to bypass intended access restrictions…
|
CWE-255 CWE-352
Credentials Management Origin Validation Error
|
CVE-2013-2762
|
2024-11-21 10:52 |
2013-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286295
|
- |
|
schneider-electric
|
modicon_m340
|
The Schneider Electric M340 BMXNOE01xx and BMXP3420xx PLC modules allow remote authenticated users to cause a denial of service (module crash) via crafted FTP traffic, as demonstrated by the FileZill…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-2761
|
2024-11-21 10:52 |
2013-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286296
|
- |
|
schneider-electric
|
modicon_m340_bmx_noc_0401_firmware modicon_m340_bmx_noe_0100_firmware modicon_m340_bmx_noe_0100h_firmware modicon_m340_bmx_noe_0110_firmware modicon_m340_bmx_noe_0110h_firmware modicon…
|
The Schneider Electric M340 PLC modules allow remote attackers to cause a denial of service (resource consumption) via unspecified vectors. NOTE: the vendor reportedly disputes this issue because it…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2013-2763
|
2024-11-21 10:52 |
2013-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286297
|
- |
|
ithemes
|
backupbuddy
|
importbuddy.php in the BackupBuddy plugin 2.2.25 for WordPress allows remote attackers to obtain configuration information via a step 0 phpinfo action, which calls the phpinfo function.
|
CWE-200
Information Exposure
|
CVE-2013-2744
|
2024-11-21 10:52 |
2013-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286298
|
- |
|
ithemes
|
backupbuddy
|
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress allows remote attackers to bypass authentication via a crafted integer in the step parameter.
|
CWE-287
Improper Authentication
|
CVE-2013-2743
|
2024-11-21 10:52 |
2013-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286299
|
- |
|
ithemes
|
backupbuddy
|
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not reliably delete itself after completing a restore operation, which makes it easier for remote …
|
NVD-CWE-Other
|
CVE-2013-2742
|
2024-11-21 10:52 |
2013-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286300
|
- |
|
ithemes
|
backupbuddy
|
importbuddy.php in the BackupBuddy plugin 1.3.4, 2.1.4, 2.2.25, 2.2.28, and 2.2.4 for WordPress does not require that authentication be enabled, which allows remote attackers to obtain sensitive info…
|
CWE-287
Improper Authentication
|
CVE-2013-2741
|
2024-11-21 10:52 |
2013-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|