|
288311
|
- |
|
opensuse ruby-lang
|
opensuse ruby
|
(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native functions, which allows context-dependent attackers to byp…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2065
|
2024-11-21 10:50 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288312
|
- |
|
mozilla
|
bugzilla
|
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1743
|
2024-11-21 10:50 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288313
|
- |
|
mozilla
|
bugzilla
|
Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote att…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1742
|
2024-11-21 10:50 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288314
|
- |
|
mozilla
|
bugzilla
|
Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allows remote attackers…
|
CWE-352
Origin Validation Error
|
CVE-2013-1734
|
2024-11-21 10:50 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288315
|
- |
|
mozilla
|
bugzilla
|
Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that modify bugs…
|
CWE-352
Origin Validation Error
|
CVE-2013-1733
|
2024-11-21 10:50 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288316
|
- |
|
mozilla
|
network_security_services
|
Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possib…
|
NVD-CWE-noinfo
|
CVE-2013-1739
|
2024-11-21 10:50 |
2013-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288317
|
- |
|
gnome
|
librsvg
|
GNOME libsvg before 2.39.0 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML Ext…
|
CWE-20
Improper Input Validation
|
CVE-2013-1881
|
2024-11-21 10:50 |
2013-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288318
|
- |
|
openstack
|
python-keystoneclient
|
The user-password-update command in python-keystoneclient before 0.2.4 accepts the new password in the --password argument, which allows local users to obtain sensitive information by listing the pro…
|
CWE-200
Information Exposure
|
CVE-2013-2013
|
2024-11-21 10:50 |
2013-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288319
|
- |
|
mongodb redhat
|
mongodb enterprise_mrg
|
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (inv…
|
CWE-20
Improper Input Validation
|
CVE-2013-1892
|
2024-11-21 10:50 |
2013-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288320
|
- |
|
squid-cache
|
squid
|
The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a ",…
|
CWE-20
Improper Input Validation
|
CVE-2013-1839
|
2024-11-21 10:50 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|