|
284301
|
- |
|
cisco
|
cloud_portal
|
Cisco Cloud Portal 9.4 allows remote attackers to read files of unspecified types via a direct request, aka Bug IDs CSCuj08426 and CSCui60889.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6708
|
2024-11-21 10:59 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284302
|
- |
|
linux
|
linux_kernel
|
The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows local users to cause a denial of service…
|
NVD-CWE-Other
|
CVE-2013-6432
|
2024-11-21 10:59 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284303
|
- |
|
linux
|
linux_kernel
|
The fib6_add function in net/ipv6/ip6_fib.c in the Linux kernel before 3.11.5 does not properly implement error-code encoding, which allows local users to cause a denial of service (NULL pointer dere…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6431
|
2024-11-21 10:59 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284304
|
- |
|
hp
|
linux_imaging_and_printing_project
|
upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows man-in-the-middle attackers to execute arbitrary co…
|
CWE-94
Code Injection
|
CVE-2013-6427
|
2024-11-21 10:59 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284305
|
- |
|
quassel-irc
|
quassel_irc
|
Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6404
|
2024-11-21 10:59 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284306
|
- |
|
drupal
|
drupal
|
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.24 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2013-6389
|
2024-11-21 10:59 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284307
|
- |
|
drupal
|
drupal
|
Drupal 6.x before 6.29 and 7.x before 7.24 uses the PHP mt_rand function to generate random numbers, which uses predictable seeds and allows remote attackers to predict security strings and bypass in…
|
CWE-310
Cryptographic Issues
|
CVE-2013-6386
|
2024-11-21 10:59 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284308
|
- |
|
drupal
|
drupal
|
The form API in Drupal 6.x before 6.29 and 7.x before 7.24, when used with unspecified third-party modules, performs form validation even when CSRF validation has failed, which might allow remote att…
|
CWE-94
Code Injection
|
CVE-2013-6385
|
2024-11-21 10:59 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284309
|
- |
|
wouter_verhelst debian canonical
|
nbd debian_linux ubuntu_linux
|
nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partia…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6410
|
2024-11-21 10:59 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284310
|
- |
|
debian
|
adequate
|
Debian adequate before 0.8.1, when run by root with the --user option, allows local users to hijack the tty and possibly gain privileges via the TIOCSTI ioctl.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6409
|
2024-11-21 10:59 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|