|
287921
|
- |
|
seamons
|
net-server
|
Net-Server, when the reverse-lookups option is enabled, does not check if the hostname resolves to the source IP address, which might allow remote attackers to bypass ACL restrictions via the hostnam…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1841
|
2024-11-21 10:50 |
2014-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287922
|
- |
|
autocomplete_widgets_project
|
autocomplete_widgets
|
The autocomplete callback in Autocomplete Widgets for Text and Number Fields (autocomplete_widgets) module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-rc1 does not properly handle node permissi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1973
|
2024-11-21 10:50 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287923
|
- |
|
mark_evans
|
dragonfly_gem
|
The Dragonfly gem 0.7 before 0.8.6 and 0.9.x before 0.9.13 for Ruby, when used with Ruby on Rails, allows remote attackers to execute arbitrary code via a crafted request.
|
CWE-94
Code Injection
|
CVE-2013-1756
|
2024-11-21 10:50 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287924
|
- |
|
owncloud
|
owncloud
|
The installation routine in ownCloud Server before 4.0.14, 4.5.x before 4.5.9, and 5.0.x before 5.0.4 uses the time function to seed the generation of the PostgreSQL database user password, which mak…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1941
|
2024-11-21 10:50 |
2014-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287925
|
- |
|
rom_walton
|
boinc
|
Stack-based buffer overflow in BOINC 6.10.58 and 6.12.34 allows remote attackers to have unspecified impact via multiple file_signature elements.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-2019
|
2024-11-21 10:50 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287926
|
- |
|
openstack fedoraproject
|
keystone fedora
|
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.
|
CWE-20
Improper Input Validation
|
CVE-2013-2014
|
2024-11-21 10:50 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287927
|
- |
|
mediawiki
|
mediawiki
|
maintenance/mwdoc-filter.php in MediaWiki before 1.20.3 allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2013-1818
|
2024-11-21 10:50 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287928
|
- |
|
mantisbt
|
mantisbt
|
Mantis Bug Tracker (aka MantisBT) 1.2.12 before 1.2.15 allows remote attackers to cause a denial of service (resource consumption) via a filter using a criteria, text search, and the "any condition" …
|
CWE-20
Improper Input Validation
|
CVE-2013-1883
|
2024-11-21 10:50 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287929
|
- |
|
opalvoip ekiga suse
|
portable_tool_library ekiga suse_linux_enterprise_software_development_kit suse_linux_enterprise_desktop
|
The Portable Tool Library (aka PTLib) before 2.10.10, as used in Ekiga before 4.0.1, does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of ser…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-1864
|
2024-11-21 10:50 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287930
|
- |
|
coscms
|
coscms
|
The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary commands via shell metacharacters in the name of an uploaded file.
|
CWE-78
OS Command
|
CVE-2013-1668
|
2024-11-21 10:50 |
2014-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|