259791
|
- |
|
apple
|
mac_os_x
|
The auto-configuration feature in Mail in Apple Mac OS X before 10.9 selects plaintext authentication for unspecified servers that support CRAM-MD5 authentication, which allows remote attackers to ob…
|
CWE-310
Cryptographic Issues
|
CVE-2013-5181
|
2013-10-25 08:40 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259792
|
- |
|
apple
|
mac_os_x
|
Mail in Apple Mac OS X before 10.9 allows remote attackers to spoof the existence of a cryptographic signature for an e-mail message by using the multipart/signed content type within an unsigned mess…
|
CWE-310
Cryptographic Issues
|
CVE-2013-5182
|
2013-10-25 08:38 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259793
|
- |
|
apple
|
mac_os_x
|
Mail in Apple Mac OS X before 10.9, when Kerberos authentication is enabled and TLS is disabled, sends invalid cleartext data, which allows remote attackers to obtain sensitive information by sniffin…
|
CWE-200
Information Exposure
|
CVE-2013-5183
|
2013-10-25 08:38 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259794
|
- |
|
apple
|
mac_os_x
|
The ldapsearch command-line program in OpenLDAP in Apple Mac OS X before 10.9 does not properly process the minssf configuration setting, which allows remote attackers to obtain sensitive information…
|
CWE-310
Cryptographic Issues
|
CVE-2013-5185
|
2013-10-25 08:37 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259795
|
- |
|
apple
|
mac_os_x
|
Power Management in Apple Mac OS X before 10.9 does not properly handle the interaction between locking and power assertions, which allows physically proximate attackers to obtain sensitive informati…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5186
|
2013-10-25 08:32 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259796
|
- |
|
apple
|
mac_os_x
|
The kernel in Apple Mac OS X before 10.9 does not properly check for errors during the processing of multicast Wi-Fi packets, which allows remote attackers to cause a denial of service (system crash)…
|
CWE-399
Resource Management Errors
|
CVE-2013-5184
|
2013-10-25 08:31 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259797
|
- |
|
apple
|
mac_os_x
|
Apple Mac OS X before 10.9 does not preserve a certain administrative system-preferences setting across software updates, which allows context-dependent attackers to bypass intended access restrictio…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5189
|
2013-10-25 08:31 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259798
|
- |
|
mozilla
|
bugzilla
|
Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that modify bugs…
|
CWE-352
Origin Validation Error
|
CVE-2013-1733
|
2013-10-25 08:29 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259799
|
- |
|
mozilla
|
bugzilla
|
Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote att…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1742
|
2013-10-25 08:29 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259800
|
- |
|
mozilla
|
bugzilla
|
Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1743
|
2013-10-25 08:28 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|