|
286391
|
- |
|
putty simon_tatham
|
putty
|
Heap-based buffer underflow in the modmul function in sshbn.c in PuTTY before 0.63 allows remote SSH servers to cause a denial of service (crash) and possibly trigger memory corruption or code execut…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4206
|
2024-11-21 10:55 |
2013-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286392
|
- |
|
ows
|
scald
|
Multiple cross-site scripting (XSS) vulnerabilities in the Scald module 7.x-1.x before 7.x-1.1 for Drupal allow remote attackers to inject arbitrary web script or HTML via the (1) flash_uri, (2) flas…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4174
|
2024-11-21 10:55 |
2013-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286393
|
- |
|
canonical php redhat
|
ubuntu_linux php enterprise_linux
|
The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Na…
|
CWE-20
Improper Input Validation
|
CVE-2013-4248
|
2024-11-21 10:55 |
2013-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286394
|
- |
|
canonical python opensuse
|
ubuntu_linux python opensuse
|
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, w…
|
CWE-20
Improper Input Validation
|
CVE-2013-4238
|
2024-11-21 10:55 |
2013-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286395
|
- |
|
redhat
|
jboss_enterprise_application_platform
|
Red Hat JBoss Enterprise Application Platform (EAP) 6.1.0 does not properly cache EJB invocations by the EJB client API, which allows remote attackers to hijack sessions by using an EJB client.
|
CWE-284
Improper Access Control
|
CVE-2013-4213
|
2024-11-21 10:55 |
2013-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286396
|
- |
|
cory_lamle
|
duplicator
|
Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pack…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4625
|
2024-11-21 10:55 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286397
|
- |
|
open-emr
|
openemr
|
Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the note parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4620
|
2024-11-21 10:55 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286398
|
- |
|
open-emr
|
openemr
|
Multiple SQL injection vulnerabilities in OpenEMR 4.1.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) start or (2) end parameter to interface/reports/custom_report_ra…
|
CWE-89
SQL Injection
|
CVE-2013-4619
|
2024-11-21 10:55 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286399
|
- |
|
alkacon
|
opencms
|
Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms before 8.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to system/workplace/views…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4600
|
2024-11-21 10:55 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286400
|
- |
|
symantec
|
backup_exec
|
Heap-based buffer overflow in the utility program in the Linux agent in Symantec Backup Exec 2010 R3 before 2010 R3 SP3 and 2012 before SP2 allows remote attackers to cause a denial of service (agent…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4575
|
2024-11-21 10:55 |
2013-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|