|
286071
|
- |
|
redhat
|
enterprise_virtualization
|
VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows privileged guest users to cause the host to become "unavailable to the managment server" via invalid XML characters in a guest agent respons…
|
NVD-CWE-Other
|
CVE-2013-4236
|
2024-11-21 10:55 |
2013-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286072
|
- |
|
putty simon_tatham
|
putty
|
The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow loca…
|
CWE-200
Information Exposure
|
CVE-2013-4208
|
2024-11-21 10:55 |
2013-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286073
|
- |
|
putty simon_tatham
|
putty
|
Buffer overflow in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) via an invalid DSA signature that is not properly handled during computation of a modula…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4207
|
2024-11-21 10:55 |
2013-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286074
|
- |
|
putty simon_tatham
|
putty
|
Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) and possibly trigger memory corruption or code execut…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4206
|
2024-11-21 10:55 |
2013-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286075
|
- |
|
ows
|
scald
|
Multiple cross-site scripting (XSS) vulnerabilities in the Scald module 7.x-1.x before 7.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) flash_uri, (2) flas…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4174
|
2024-11-21 10:55 |
2013-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286076
|
- |
|
canonical php redhat
|
ubuntu_linux php enterprise_linux
|
The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Na…
|
CWE-20
Improper Input Validation
|
CVE-2013-4248
|
2024-11-21 10:55 |
2013-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286077
|
- |
|
canonical python opensuse
|
ubuntu_linux python opensuse
|
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, w…
|
CWE-20
Improper Input Validation
|
CVE-2013-4238
|
2024-11-21 10:55 |
2013-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286078
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
|
CWE-284
Improper Access Control
|
CVE-2013-4213
|
2024-11-21 10:55 |
2013-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286079
|
- |
|
cory_lamle
|
duplicator
|
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pack…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4625
|
2024-11-21 10:55 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286080
|
- |
|
open-emr
|
openemr
|
Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the note parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4620
|
2024-11-21 10:55 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|