|
284971
|
- |
|
dovecot
|
dovecot
|
checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attachin…
|
CWE-287
Improper Authentication
|
CVE-2013-6171
|
2024-11-21 10:58 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284972
|
- |
|
twibright
|
links
|
Integer overflow in Links before 2.8 allows remote attackers to cause a denial of service (crash) via crafted HTML tables.
|
CWE-189
Numeric Errors
|
CVE-2013-6050
|
2024-11-21 10:58 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284973
|
- |
|
claroline
|
claroline
|
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.11.9 allow remote attackers to inject arbitrary web script or HTML via the (1) box parameter to messaging/messagebox.php, cid…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6267
|
2024-11-21 10:58 |
2013-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284974
|
- |
|
cybozu
|
garoon
|
Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6004
|
2024-11-21 10:58 |
2013-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284975
|
- |
|
cybozu
|
garoon
|
CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers via unspecified vect…
|
CWE-20
Improper Input Validation
|
CVE-2013-6003
|
2024-11-21 10:58 |
2013-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284976
|
- |
|
cybozu
|
garoon
|
The server in Cybozu Garoon before 3.7 SP1 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.
|
CWE-399
Resource Management Errors
|
CVE-2013-6002
|
2024-11-21 10:58 |
2013-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284977
|
- |
|
cybozu
|
garoon
|
SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2013-6001
|
2024-11-21 10:58 |
2013-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284978
|
- |
|
tattyan
|
tattyan_hptown
|
Directory traversal vulnerability in Tattyan HP TOWN before 5_10_1 allows remote attackers to read arbitrary files via a .. (dot dot) in a request.
|
CWE-22
Path Traversal
|
CVE-2013-6000
|
2024-11-21 10:58 |
2013-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284979
|
- |
|
att
|
connect_participant_application
|
Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code via a malformed .SVT file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-6029
|
2024-11-21 10:58 |
2013-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284980
|
- |
|
ibm
|
qradar_security_information_and_event_manager
|
Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6307
|
2024-11-21 10:58 |
2013-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|