|
290511
|
- |
|
openstack
|
havana grizzly folsom
|
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by cr…
|
CWE-399
Resource Management Errors
|
CVE-2013-2096
|
2024-11-21 10:51 |
2013-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290512
|
- |
|
wordpress
|
wordpress
|
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-si…
|
CWE-79 CWE-16
Cross-site Scripting Configuration
|
CVE-2013-2205
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290513
|
- |
|
wordpress tinymce
|
wordpress media
|
moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extracti…
|
CWE-20
Improper Input Validation
|
CVE-2013-2204
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290514
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an X…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2203
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290515
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related t…
|
CWE-200
Information Exposure
|
CVE-2013-2202
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290516
|
- |
|
wordpress
|
wordpress
|
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editi…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2201
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290517
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspeci…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2200
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290518
|
- |
|
wordpress
|
wordpress
|
The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vuln…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2199
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290519
|
- |
|
hp
|
procurve_switch h3c_switch h3c_ethernet_switch h3c_router 3com_router procurve_router 3com_switch h3c_routing_switch h3c_processing_module h3c_high_performance_main_process…
|
Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and s…
|
NVD-CWE-noinfo
|
CVE-2013-2341
|
2024-11-21 10:51 |
2013-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290520
|
- |
|
linux
|
linux_kernel
|
The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from k…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-2237
|
2024-11-21 10:51 |
2013-07-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|