|
287681
|
5.3 |
MEDIUM
Network
|
horde opensuse debian
|
groupware opensuse debian_linux
|
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
|
CWE-352
Origin Validation Error
|
CVE-2013-6365
|
2024-11-21 10:59 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287682
|
8.8 |
HIGH
Network
|
horde debian
|
groupware debian_linux
|
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2013-6364
|
2024-11-21 10:59 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287683
|
5.4 |
MEDIUM
Network
|
ibm
|
spss_modeler
|
IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855.
|
CWE-284
Improper Access Control
|
CVE-2013-6739
|
2024-11-21 10:59 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287684
|
7.8 |
HIGH
Local
|
s3dvt_project
|
s3dvt
|
The (1) pty_init_terminal and (2) pipe_init_terminal functions in main.c in s3dvt 0.2.2 and earlier allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and ea…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6876
|
2024-11-21 10:59 |
2018-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287685
|
5.4 |
MEDIUM
Network
|
redhat
|
jbpm
|
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6465
|
2024-11-21 10:59 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287686
|
9.8 |
CRITICAL
Network
|
seagate
|
blackarmor_nas_220_firmware
|
Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.
|
CWE-77
Command Injection
|
CVE-2013-6924
|
2024-11-21 10:59 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287687
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Google Chrome caches TLS sessions before certificate validation occurs.
|
CWE-295
Improper Certificate Validation
|
CVE-2013-6662
|
2024-11-21 10:59 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287688
|
7.5 |
HIGH
Network
|
google
|
skia
|
SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).
|
NVD-CWE-noinfo
|
CVE-2013-6648
|
2024-11-21 10:59 |
2017-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287689
|
9.8 |
CRITICAL
Network
|
google
|
chrome
|
A use-after-free in AnimationController::endAnimationUpdate in Google Chrome.
|
CWE-416
Use After Free
|
CVE-2013-6647
|
2024-11-21 10:59 |
2017-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287690
|
3.1 |
LOW
Network
|
cloudera
|
cdh
|
The JobHistory Server in Cloudera CDH 4.x before 4.6.0 and 5.x before 5.0.0 Beta 2, when using MRv2/YARN with HTTP authentication, allows remote authenticated users to obtain sensitive job informatio…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6446
|
2024-11-21 10:59 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|