259981
|
- |
|
verizon
|
fios_actiontec_mi424wr-gen31_router_firmware fios_actiontec_mi424wr-gen31_router
|
Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allow remote attackers to hijack the authentication o…
|
CWE-352
Origin Validation Error
|
CVE-2013-0126
|
2013-10-8 05:31 |
2013-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259982
|
- |
|
cisco
|
ios ios_xe
|
Memory leak in Cisco IOS 12.2, 15.1, and 15.2; IOS XE 3.4.2S through 3.4.5S; and IOS XE 3.6.xS before 3.6.1S allows remote attackers to cause a denial of service (memory consumption or device reload)…
|
CWE-399
Resource Management Errors
|
CVE-2013-5473
|
2013-10-8 05:26 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259983
|
- |
|
graphite_project
|
graphite
|
The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a …
|
CWE-94
Code Injection
|
CVE-2013-5093
|
2013-10-8 05:25 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259984
|
- |
|
cisco
|
ios
|
The Zone-Based Firewall (ZFW) feature in Cisco IOS 15.1 through 15.2, when content filtering or HTTP ALG inspection is enabled, allows remote attackers to cause a denial of service (device reload or …
|
CWE-20
Improper Input Validation
|
CVE-2013-5476
|
2013-10-8 05:18 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259985
|
- |
|
graphite_project
|
graphite
|
Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to (1) remote_storage.py, (2) st…
|
CWE-94
Code Injection
|
CVE-2013-5942
|
2013-10-8 05:17 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259986
|
- |
|
graphite_project
|
graphite
|
Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-5943
|
2013-10-8 05:17 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259987
|
- |
|
cisco
|
ios
|
The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka …
|
CWE-20
Improper Input Validation
|
CVE-2013-5480
|
2013-10-8 05:16 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259988
|
- |
|
cisco
|
ios
|
The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka …
|
CWE-20
Improper Input Validation
|
CVE-2013-5479
|
2013-10-8 05:15 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259989
|
- |
|
cisco
|
ios ios_xe
|
Cisco IOS 15.0 through 15.3 and IOS XE 3.2 through 3.8, when a VRF interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via crafted UDP RSVP packets, aka Bug…
|
CWE-20
Improper Input Validation
|
CVE-2013-5478
|
2013-10-8 05:14 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259990
|
- |
|
cisco
|
ios
|
The T1/E1 driver-queue functionality in Cisco IOS 12.2 and 15.0 through 15.3, when an HDLC32 driver is used, allows remote attackers to cause a denial of service (interface queue wedge) via bursty ne…
|
CWE-20
Improper Input Validation
|
CVE-2013-5477
|
2013-10-8 05:13 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|