|
284001
|
7.8 |
HIGH
Local
|
slackware
|
slackware_linux
|
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to…
|
CWE-20
Improper Input Validation
|
CVE-2013-7172
|
2024-11-21 11:00 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284002
|
9.8 |
CRITICAL
Network
|
slackware
|
slackware_linux
|
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root …
|
CWE-20
Improper Input Validation
|
CVE-2013-7171
|
2024-11-21 11:00 |
2019-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284003
|
7.5 |
HIGH
Network
|
clamav debian fedoraproject
|
clamav debian_linux fedora
|
ClamAV before 0.97.7: dbg_printhex possible information leak
|
CWE-200
Information Exposure
|
CVE-2013-7089
|
2024-11-21 11:00 |
2019-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284004
|
9.8 |
CRITICAL
Network
|
clamav debian fedoraproject
|
clamav debian_linux fedora
|
ClamAV before 0.97.7 has buffer overflow in the libclamav component
|
CWE-120
Classic Buffer Overflow
|
CVE-2013-7088
|
2024-11-21 11:00 |
2019-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284005
|
9.8 |
CRITICAL
Network
|
clamav debian fedoraproject
|
clamav debian_linux fedora
|
ClamAV before 0.97.7 has WWPack corrupt heap memory
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-7087
|
2024-11-21 11:00 |
2019-11-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284006
|
7.5 |
HIGH
Network
|
projectfloodlight
|
open_sdn_controller
|
A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to selectively disconnect individual switches from t…
|
CWE-20
Improper Input Validation
|
CVE-2013-7333
|
2024-11-21 11:00 |
2019-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284007
|
9.8 |
CRITICAL
Network
|
xstream_project
|
xstream
|
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed inpu…
|
CWE-78
OS Command
|
CVE-2013-7285
|
2024-11-21 11:00 |
2019-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284008
|
5.5 |
MEDIUM
Local
|
gitolite
|
gitolite
|
gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.
|
CWE-200
Information Exposure
|
CVE-2013-7203
|
2024-11-21 11:00 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284009
|
8.1 |
HIGH
Network
|
paypal
|
paypal
|
The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7202
|
2024-11-21 11:00 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284010
|
7.4 |
HIGH
Network
|
paypal
|
paypal
|
WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
|
CWE-295
Improper Certificate Validation
|
CVE-2013-7201
|
2024-11-21 11:00 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|