|
288761
|
7.8 |
HIGH
Local
|
hexagongeospatial
|
erdas_er_viewer
|
ERDAS ER Viewer 13.0 has dwmapi.dll and irml.dll libraries arbitrary code execution vulnerabilities
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2013-0725
|
2024-11-21 10:48 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288762
|
6.1 |
MEDIUM
Network
|
boltwire
|
boltwire
|
Cross-site scripting (XSS) vulnerability in BoltWire 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the fieldnames parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-0737
|
2024-11-21 10:48 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288763
|
9.8 |
CRITICAL
Network
|
ffmpeg
|
ffmpeg
|
The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.
|
NVD-CWE-noinfo
|
CVE-2013-0870
|
2024-11-21 10:48 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288764
|
- |
|
canonical
|
ubuntu_linux
|
The OpenStack Nova (python-nova) package 1:2013.2.3-0 before 1:2013.2.3-0ubuntu1.2 and 1:2014.1-0 before 1:2014.1-0ubuntu1.2 and Openstack Cinder (python-cinder) package 1:2013.2.3-0 before 1:2013.2.…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1068
|
2024-11-21 10:48 |
2014-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288765
|
- |
|
corel
|
paintshop_pro_x5 paintshop_pro_x6
|
Untrusted search path vulnerability in Corel PaintShop Pro X5 and X6 16.0.0.113, 15.2.0.2, and earlier allows local users to execute arbitrary code and conduct DLL hijacking attacks via a Trojan hors…
|
NVD-CWE-Other
|
CVE-2013-0733
|
2024-11-21 10:48 |
2014-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288766
|
- |
|
wpshopstyling
|
wp-ecommerce-shop-styling
|
PHP remote file inclusion vulnerability in includes/generate-pdf.php in the WP ecommerce Shop Styling plugin for WordPress before 1.8 allows remote attackers to execute arbitrary PHP code via a URL i…
|
CWE-94
Code Injection
|
CVE-2013-0724
|
2024-11-21 10:48 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288767
|
- |
|
dell
|
openmanage_server_administrator
|
Open redirect vulnerability in Dell OpenManage Server Administrator (OMSA) before 7.3.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the …
|
CWE-20
Improper Input Validation
|
CVE-2013-0740
|
2024-11-21 10:48 |
2014-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288768
|
- |
|
cartpauj
|
mingle-forum
|
Multiple SQL injection vulnerabilities in wpf.class.php in the Mingle Forum plugin before 1.0.34 for WordPress allow remote attackers to execute arbitrary SQL commands via the id parameter in a viewt…
|
CWE-89
SQL Injection
|
CVE-2013-0735
|
2024-11-21 10:48 |
2014-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288769
|
- |
|
tracker-software
|
pdf-xchange_viewer
|
Heap-based buffer overflow in Tracker Software PDF-XChange before 2.5.208 allows remote attackers to execute arbitrary code via a crafted Define Huffman Table header in a JPEG image file stream in a …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-0729
|
2024-11-21 10:48 |
2014-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288770
|
- |
|
gpeasy
|
gpeasy_cms
|
Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS 3.5.2 and earlier allows remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0807
|
2024-11-21 10:48 |
2014-03-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|