|
285161
|
- |
|
david_king canonical
|
vino ubuntu_linux
|
The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error …
|
CWE-20
Improper Input Validation
|
CVE-2013-5745
|
2024-11-21 10:58 |
2013-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285162
|
- |
|
metaclassy
|
byword
|
The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite arbitrary files via the name and text parameters in …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5725
|
2024-11-21 10:58 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285163
|
- |
|
cdsincdesign
|
simple_dropbox_upload_form
|
Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executab…
|
NVD-CWE-Other
|
CVE-2013-5963
|
2024-11-21 10:58 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285164
|
- |
|
envato
|
complete_gallery_manager_plugin
|
Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uplo…
|
NVD-CWE-Other
|
CVE-2013-5962
|
2024-11-21 10:58 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285165
|
- |
|
danny_morris
|
lazy_seo
|
Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a…
|
NVD-CWE-Other
|
CVE-2013-5961
|
2024-11-21 10:58 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285166
|
- |
|
adcisolutions
|
node_view_permissions
|
The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remote attackers to obtain sensitive information by rea…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5965
|
2024-11-21 10:58 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285167
|
- |
|
joachim_noreiko
|
flag_module
|
Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "Administer flags" permission to in…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5964
|
2024-11-21 10:58 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285168
|
- |
|
owasp
|
enterprise_security_api
|
The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0.1 does not properly resist tampering with serial…
|
CWE-310
Cryptographic Issues
|
CVE-2013-5960
|
2024-11-21 10:58 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285169
|
- |
|
bluecoat
|
proxysgos proxysg
|
Blue Coat ProxySG before 6.2.14.1, 6.3.x, 6.4.x, and 6.5 before 6.5.2 allows remote attackers to cause a denial of service (memory consumption and dropped connections) via a recursive href in an HTML…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5959
|
2024-11-21 10:58 |
2013-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285170
|
- |
|
graphite_project
|
graphite
|
Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-5943
|
2024-11-21 10:58 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|