|
286111
|
- |
|
dkorunic
|
pam_s\/key
|
A certain Gentoo patch for the PAM S/Key module does not properly clear credentials from memory, which allows local users to obtain sensitive information by reading system memory.
|
CWE-255
Credentials Management
|
CVE-2013-4285
|
2024-11-21 10:55 |
2014-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286112
|
- |
|
debian
|
ppthtml
|
Heap-based buffer overflow in the __OLEdecode function in ppthtml 0.5.1 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .ppt…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4565
|
2024-11-21 10:55 |
2014-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286113
|
- |
|
freedesktop
|
poppler
|
The openTempFile function in goo/gfile.cc in Xpdf and Poppler 0.24.3 and earlier, when running on a system other than Unix, allows local users to overwrite arbitrary files via a symlink attack on tem…
|
CWE-59
Link Following
|
CVE-2013-4472
|
2024-11-21 10:55 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286114
|
- |
|
imapsync_project
|
imapsync
|
imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to the developer's site.
|
CWE-200
Information Exposure
|
CVE-2013-4279
|
2024-11-21 10:55 |
2014-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286115
|
- |
|
uclouvain
|
openjpeg
|
Stack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified impact via unknown vectors to (1) lib/openjp3d/opj_jp3d_compress.c, (2) bin/jp3d/convert.c, or (3) lib…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4290
|
2024-11-21 10:55 |
2014-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286116
|
- |
|
uclouvain
|
openjpeg
|
Multiple integer overflows in lib/openjp3d/jp3d.c in OpenJPEG before 1.5.2 allow remote attackers to have unspecified impact and vectors, which trigger a heap-based buffer overflow.
|
CWE-189
Numeric Errors
|
CVE-2013-4289
|
2024-11-21 10:55 |
2014-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286117
|
- |
|
hitmyserver
|
hms_testimonials
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for request…
|
CWE-352
Origin Validation Error
|
CVE-2013-4240
|
2024-11-21 10:55 |
2014-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286118
|
- |
|
samba canonical
|
samba ubuntu_linux
|
Samba 3.x before 3.6.23, 4.0.x before 4.0.16, and 4.1.x before 4.1.6 does not enforce the password-guessing protection mechanism for all interfaces, which makes it easier for remote attackers to obta…
|
CWE-255
Credentials Management
|
CVE-2013-4496
|
2024-11-21 10:55 |
2014-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286119
|
- |
|
vicidial
|
vicidial
|
Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQ…
|
CWE-89
SQL Injection
|
CVE-2013-4467
|
2024-11-21 10:55 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286120
|
- |
|
php
|
xhprof
|
Cross-site scripting (XSS) vulnerability in XHProf before 0.9.4 allows remote attackers to inject arbitrary web script or HTML via the run parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4433
|
2024-11-21 10:55 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|