|
285191
|
- |
|
wireshark
|
wireshark
|
The dissect_nbap_T_dCH_ID function in epan/dissectors/packet-nbap.c in the NBAP dissector in Wireshark 1.8.x before 1.8.10 and 1.10.x before 1.10.2 does not restrict the dch_id value, which allows re…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5718
|
2024-11-21 10:58 |
2013-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285192
|
- |
|
wireshark
|
wireshark
|
The Bluetooth HCI ACL dissector in Wireshark 1.10.x before 1.10.2 does not properly maintain a certain free list, which allows remote attackers to cause a denial of service (application crash) via a …
|
CWE-20
Improper Input Validation
|
CVE-2013-5717
|
2024-11-21 10:58 |
2013-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285193
|
- |
|
intel
|
qs77_chipset trusted_execution_technology_sinit_authenticated_code_module q67_express_chipset c206_chipset qm77_chipset mobile_intel_qs67_chipset mobile_intel_qm67_chipset c216_c…
|
Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C20…
|
NVD-CWE-noinfo
|
CVE-2013-5740
|
2024-11-21 10:58 |
2013-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285194
|
- |
|
debian
|
phpbb3
|
Phpbb3 before 3.0.11-4 for Debian GNU/Linux uses world-writable permissions for cache files, which allows local users to modify the file contents via standard filesystem write operations.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5724
|
2024-11-21 10:58 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285195
|
- |
|
sap
|
netweaver
|
SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD0_DELETE_DERIVATION_TABLE."
|
CWE-89
SQL Injection
|
CVE-2013-5723
|
2024-11-21 10:58 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285196
|
- |
|
wordpress
|
wordpress
|
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) at…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5739
|
2024-11-21 10:58 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285197
|
- |
|
wordpress
|
wordpress
|
The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it eas…
|
CWE-20
Improper Input Validation
|
CVE-2013-5738
|
2024-11-21 10:58 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285198
|
- |
|
gomlab
|
gom_player
|
Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.
|
CWE-20
Improper Input Validation
|
CVE-2013-5716
|
2024-11-21 10:58 |
2013-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285199
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2013-5594
|
2024-11-21 10:57 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285200
|
7.5 |
HIGH
Network
|
aicorporation
|
risknet_acquirer
|
RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
|
CWE-200
Information Exposure
|
CVE-2013-5687
|
2024-11-21 10:57 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|