|
289191
|
- |
|
seagate
|
blackarmor_nas_220_firmware blackarmor_nas_220
|
Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inject arbitrary web script or HTML via the (1) full…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6923
|
2024-11-21 10:59 |
2014-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289192
|
- |
|
x
|
libxfont
|
Stack-based buffer overflow in the bdfReadCharacters function in bitmap/bdfread.c in X.Org libXfont 1.1 through 1.4.6 allows remote attackers to cause a denial of service (crash) or possibly execute …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-6462
|
2024-11-21 10:59 |
2014-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289193
|
- |
|
redhat
|
libvirt
|
The lxcDomainGetMemoryParameters method in lxc/lxc_driver.c in libvirt 1.0.5 through 1.2.0 does not properly check the status of LXC guests when reading memory tunables, which allows local users to c…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6436
|
2024-11-21 10:59 |
2014-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289194
|
- |
|
apache
|
libcloud
|
Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.
|
CWE-200
Information Exposure
|
CVE-2013-6480
|
2024-11-21 10:59 |
2014-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289195
|
- |
|
openstack
|
havana
|
Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive…
|
CWE-200
Information Exposure
|
CVE-2013-6419
|
2024-11-21 10:59 |
2014-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289196
|
- |
|
devscripts_devel_team
|
devscripts
|
Uscan in devscripts before 2.13.9 allows remote attackers to execute arbitrary code via a crafted tarball.
|
NVD-CWE-noinfo
|
CVE-2013-6888
|
2024-11-21 10:59 |
2014-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289197
|
- |
|
cru-inc
|
ditto_forensic_fieldstation_firmware ditto_forensic_fieldstation
|
The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges.
|
CWE-255
Credentials Management
|
CVE-2013-6884
|
2024-11-21 10:59 |
2014-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289198
|
- |
|
cru-inc
|
ditto_forensic_fieldstation_firmware ditto_forensic_fieldstation
|
CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the …
|
CWE-78
OS Command
|
CVE-2013-6881
|
2024-11-21 10:59 |
2014-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289199
|
- |
|
hp
|
linux_imaging_and_printing_project
|
base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.11 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/hp-pkservice.log temporary file.
|
CWE-59
Link Following
|
CVE-2013-6402
|
2024-11-21 10:59 |
2014-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289200
|
- |
|
openssl
|
openssl
|
The DTLS retransmission implementation in OpenSSL 1.0.0 before 1.0.0l and 1.0.1 before 1.0.1f does not properly maintain data structures for digest and encryption contexts, which might allow man-in-t…
|
CWE-310
Cryptographic Issues
|
CVE-2013-6450
|
2024-11-21 10:59 |
2014-01-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|