|
283641
|
7.5 |
HIGH
Network
|
mcafee
|
saas_control_console_platform
|
A directory traversal vulnerability in the web application in McAfee (now Intel Security) SaaS Control Console (SCC) Platform 6.14 before patch 1070, and 6.15 before patch 1076 allows unauthenticated…
|
CWE-22
Path Traversal
|
CVE-2013-7462
|
2024-11-21 11:01 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283642
|
5.5 |
MEDIUM
Local
|
mcafee
|
change_control application_control
|
A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write…
|
CWE-284
Improper Access Control
|
CVE-2013-7461
|
2024-11-21 11:01 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283643
|
5.5 |
MEDIUM
Local
|
mcafee
|
change_control application_control
|
A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part …
|
CWE-284
Improper Access Control
|
CVE-2013-7460
|
2024-11-21 11:01 |
2017-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283644
|
9.8 |
CRITICAL
Network
|
dlitz fedoraproject
|
pycrypto fedora
|
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv p…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-7459
|
2024-11-21 11:01 |
2017-02-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283645
|
6.1 |
MEDIUM
Network
|
nodejs
|
node.js
|
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7454
|
2024-11-21 11:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283646
|
6.1 |
MEDIUM
Network
|
nodejs
|
node.js
|
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7453
|
2024-11-21 11:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283647
|
6.1 |
MEDIUM
Network
|
nodejs
|
node.js
|
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7452
|
2024-11-21 11:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283648
|
6.1 |
MEDIUM
Network
|
nodejs
|
node.js
|
The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7451
|
2024-11-21 11:01 |
2017-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283649
|
3.3 |
LOW
Local
|
redislabs debian
|
redis debian_linux
|
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
|
CWE-200
Information Exposure
|
CVE-2013-7458
|
2024-11-21 11:01 |
2016-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283650
|
7.6 |
HIGH
Network
|
libgd
|
libgd
|
gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allows remote attackers to cause a denial of service (…
|
CWE-125
Out-of-bounds Read
|
CVE-2013-7456
|
2024-11-21 11:01 |
2016-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|