|
286131
|
7.8 |
HIGH
Local
|
extensis
|
mrsid
|
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.
|
CWE-20
Improper Input Validation
|
CVE-2013-3945
|
2024-11-21 10:54 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286132
|
7.8 |
HIGH
Local
|
extensis
|
mrsid
|
Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via an IMAGE tag.
|
CWE-787
Out-of-bounds Write
|
CVE-2013-3944
|
2024-11-21 10:54 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286133
|
7.5 |
HIGH
Network
|
supermicro citrix
|
smt_x9_firmware smt_x8_firmware netscaler_sdx_firmware netscaler_firmware netscaler_sd-wan_firmware
|
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generat…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2013-3620
|
2024-11-21 10:54 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286134
|
6.1 |
MEDIUM
Network
|
opsview
|
opsview opsview_core
|
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3936
|
2024-11-21 10:54 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286135
|
8.8 |
HIGH
Network
|
opsview
|
opsview opsview_core
|
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.1 and Opsview Core before 20130522 allows remote attackers to hijack the authentication of administrators for requests that chang…
|
CWE-352
Origin Validation Error
|
CVE-2013-3935
|
2024-11-21 10:54 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286136
|
7.8 |
HIGH
Local
|
gksu-polkit_project fedoraproject
|
gksu-polkit fedora
|
gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.
|
CWE-269
Improper Privilege Management
|
CVE-2013-4161
|
2024-11-21 10:54 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286137
|
7.5 |
HIGH
Network
|
ovislink
|
airlive_poe2600hd_firmware
|
AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2013-3691
|
2024-11-21 10:54 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286138
|
6.1 |
MEDIUM
Network
|
smokeping debian fedoraproject
|
smokeping debian_linux fedora
|
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
|
CWE-79
Cross-site Scripting
|
CVE-2013-4158
|
2024-11-21 10:54 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286139
|
7.5 |
HIGH
Network
|
kde debian
|
kde-workspace debian_linux
|
kde-workspace before 4.10.5 has a memory leak in plasma desktop
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2013-4133
|
2024-11-21 10:54 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286140
|
7.5 |
HIGH
Network
|
theforeman
|
katello
|
Katello has a Denial of Service vulnerability in API OAuth authentication
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2013-4120
|
2024-11-21 10:54 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|