|
285011
|
- |
|
isc
|
bind
|
The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P1, 9.9.3-S1, 9.9.4-S1, and other products, does no…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6230
|
2024-11-21 10:58 |
2013-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285012
|
- |
|
roundcube
|
webmail
|
steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read …
|
CWE-89
SQL Injection
|
CVE-2013-6172
|
2024-11-21 10:58 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285013
|
- |
|
citrix
|
xendesktop
|
Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6077
|
2024-11-21 10:58 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285014
|
- |
|
apple
|
motion
|
Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denial of service (application crash) via a (1) large or (2) small value in the subv…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2013-6114
|
2024-11-21 10:58 |
2013-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285015
|
- |
|
modpagespeed
|
mod_pagespeed
|
Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.x, 1.0.22.7, 1.1.x, 1.24.1, 1.3.25.1 through 1.3.25.4, 1.4.26.1 through 1.4.26.4, 1.5.27.1 through 1.5.27.3, and 1.6.29.1 throug…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6111
|
2024-11-21 10:58 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285016
|
- |
|
tvt
|
dvr dvr_firmware
|
Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI.
|
CWE-22
Path Traversal
|
CVE-2013-6023
|
2024-11-21 10:58 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285017
|
- |
|
strongswan
|
strongswan
|
strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and charon daemon crash) via a crafted IKEv1 fragmentation packet.
|
NVD-CWE-Other
|
CVE-2013-6076
|
2024-11-21 10:58 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285018
|
- |
|
strongswan
|
strongswan
|
The compare_dn function in utils/identification.c in strongSwan 4.3.3 through 5.1.1 allows (1) remote attackers to cause a denial of service (out-of-bounds read, NULL pointer dereference, and daemon …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-6075
|
2024-11-21 10:58 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285019
|
- |
|
cart66
|
cart66_lite_plugin
|
Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers to hijack the authentication of administrators for…
|
CWE-352
Origin Validation Error
|
CVE-2013-5977
|
2024-11-21 10:58 |
2013-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285020
|
- |
|
ca broadcom
|
web_agents siteminder
|
Cross-site scripting (XSS) vulnerability in CA SiteMinder 12.0 through 12.51, and SiteMinder 6 Web Agents, allows remote attackers to inject arbitrary web script or HTML via vectors involving a " (do…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5968
|
2024-11-21 10:58 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|