|
288301
|
- |
|
gnu
|
gnutls
|
The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the pr…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1619
|
2024-11-21 10:50 |
2013-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288302
|
- |
|
opera
|
opera_browser
|
The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which allows remote attack…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1618
|
2024-11-21 10:50 |
2013-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288303
|
- |
|
opera
|
opera_browser
|
Opera before 12.13 does not send CORS preflight requests in all required cases, which allows remote attackers to bypass a CSRF protection mechanism via a crafted web site that triggers a CORS request.
|
CWE-352
Origin Validation Error
|
CVE-2013-1639
|
2024-11-21 10:50 |
2013-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288304
|
- |
|
opera
|
opera_browser
|
Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.
|
CWE-94
Code Injection
|
CVE-2013-1638
|
2024-11-21 10:50 |
2013-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288305
|
- |
|
opera
|
opera_browser
|
Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events.
|
CWE-94
Code Injection
|
CVE-2013-1637
|
2024-11-21 10:50 |
2013-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288306
|
9.8 |
CRITICAL
Network
|
cardozatechnologies
|
wordpress_poll
|
Multiple security bypass vulnerabilities in the editAnswer, deleteAnswer, addAnswer, and deletePoll functions in WordPress Poll Plugin 34.5 for WordPress allow a remote attacker to add, edit, and del…
|
CWE-89
SQL Injection
|
CVE-2013-1401
|
2024-11-21 10:49 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288307
|
9.8 |
CRITICAL
Network
|
cardozatechnologies
|
wordpress_poll
|
Multiple SQL injection vulnerabilities in CWPPoll.js in WordPress Poll Plugin 34.5 for WordPress allow attackers to execute arbitrary SQL commands via the pollid or poll_id parameter in a viewPollRes…
|
CWE-89
SQL Injection
|
CVE-2013-1400
|
2024-11-21 10:49 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288308
|
6.1 |
MEDIUM
Network
|
perforce
|
p4web
|
Perforce P4web 2011.1 and 2012.1 has multiple XSS vulnerabilities
|
CWE-79
Cross-site Scripting
|
CVE-2013-1410
|
2024-11-21 10:49 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288309
|
9.8 |
CRITICAL
Network
|
pdfkit_project
|
pdfkit
|
Ruby PDFKit gem prior to 0.5.3 has a Code Execution Vulnerability
|
CWE-20
Improper Input Validation
|
CVE-2013-1607
|
2024-11-21 10:49 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288310
|
9.8 |
CRITICAL
Network
|
sonicwall
|
analyzer global_management_system viewpoint universal_management_appliance
|
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7.0; Universal Management Appliance (UMA) 5.1, 6.0, and 7.0 and Vi…
|
CWE-287
Improper Authentication
|
CVE-2013-1359
|
2024-11-21 10:49 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|