|
290151
|
- |
|
pd-admin
|
pd-admin
|
Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject arbitrary web script or HTML via (1) the WebFTP Overview "Create new directory" …
|
CWE-79
Cross-site Scripting
|
CVE-2013-0129
|
2024-11-21 10:46 |
2013-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290152
|
- |
|
arecont
|
vision_av1355dn_megadome_camera
|
The Arecont Vision AV1355DN MegaDome camera allows remote attackers to cause a denial of service (video-capture outage) via a packet to UDP port 69.
|
NVD-CWE-noinfo
|
CVE-2013-0139
|
2024-11-21 10:46 |
2013-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290153
|
- |
|
parallels
|
parallels_plesk_panel
|
Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Parallels Plesk Panel 11.0.9 allows local users to gain privileges via a crafted PATH environment variable.
|
NVD-CWE-Other
|
CVE-2013-0133
|
2024-11-21 10:46 |
2013-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290154
|
- |
|
parallels
|
parallels_plesk_panel
|
The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing cr…
|
CWE-94
Code Injection
|
CVE-2013-0132
|
2024-11-21 10:46 |
2013-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290155
|
- |
|
microsoft
|
windows_defender
|
The Microsoft Antimalware Client in Windows Defender on Windows 8 and Windows RT uses an incorrect pathname for MsMpEng.exe, which allows local users to gain privileges via a crafted application, aka…
|
CWE-20
Improper Input Validation
|
CVE-2013-0078
|
2024-11-21 10:46 |
2013-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290156
|
- |
|
airdroid
|
airdroid
|
Cross-site scripting (XSS) vulnerability in the web interface in AirDroid allows remote attackers to inject arbitrary web script or HTML via a crafted text message that is transmitted by a managed ph…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0134
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290157
|
- |
|
nvidia
|
gpu_driver
|
Buffer overflow in the NVIDIA GPU driver before 304.88, 310.x before 310.44, and 313.x before 313.30 for the X Window System on UNIX, when NoScanout mode is enabled, allows remote authenticated users…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-0131
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290158
|
- |
|
nvidia
|
driver
|
daemonu.exe (aka the NVIDIA Update Service Daemon), as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service pa…
|
NVD-CWE-Other
|
CVE-2013-0111
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290159
|
- |
|
nvidia
|
driver
|
nvSCPAPISvr.exe in the NVIDIA Stereoscopic 3D Driver service, as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the …
|
NVD-CWE-Other
|
CVE-2013-0110
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290160
|
- |
|
chatelao
|
php_address_book
|
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) address…
|
CWE-89
SQL Injection
|
CVE-2013-0135
|
2024-11-21 10:46 |
2013-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|