|
287291
|
- |
|
redhat
|
openstack
|
nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary n…
|
CWE-59
Link Following
|
CVE-2013-2029
|
2024-11-21 10:50 |
2013-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287292
|
- |
|
redhat t-mobile busybox
|
enterprise_linux tm-ac1900 busybox
|
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vector…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1813
|
2024-11-21 10:50 |
2013-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287293
|
- |
|
mozilla
|
network_security_services
|
Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.
|
CWE-189
Numeric Errors
|
CVE-2013-1741
|
2024-11-21 10:50 |
2013-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287294
|
- |
|
openvpn opensuse
|
openvpn openvpn_access_server opensuse
|
The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparis…
|
CWE-200
Information Exposure
|
CVE-2013-2061
|
2024-11-21 10:50 |
2013-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287295
|
- |
|
mediawiki fedoraproject gentoo
|
mediawiki fedora linux
|
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attacke…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2032
|
2024-11-21 10:50 |
2013-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287296
|
- |
|
gentoo mediawiki
|
linux mediawiki
|
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 encoded sequences in …
|
CWE-79
Cross-site Scripting
|
CVE-2013-2031
|
2024-11-21 10:50 |
2013-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287297
|
- |
|
linux
|
linux_kernel
|
The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-2058
|
2024-11-21 10:50 |
2013-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287298
|
- |
|
opensuse ruby-lang
|
opensuse ruby
|
(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native functions, which allows context-dependent attackers to byp…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2065
|
2024-11-21 10:50 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287299
|
- |
|
mozilla
|
bugzilla
|
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1743
|
2024-11-21 10:50 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287300
|
- |
|
mozilla
|
bugzilla
|
Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote att…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1742
|
2024-11-21 10:50 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|