261061
|
- |
|
zoneminder
|
zoneminder
|
Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) view, (2) request, or (3) action parameter.
|
CWE-22
Path Traversal
|
CVE-2013-0332
|
2013-03-22 01:31 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261062
|
- |
|
zugec_ivan
|
keyboard_shortcut_utility
|
The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal does not properly check node restrictions, which allows (1) remote authenticated users with the "view shortcuts" permission to r…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0226
|
2013-03-21 23:45 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261063
|
- |
|
leighton_whiting
|
mark_complete
|
Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown v…
|
CWE-352
Origin Validation Error
|
CVE-2013-0207
|
2013-03-21 23:21 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261064
|
- |
|
debian
|
latd
|
Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long strin…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-0251
|
2013-03-21 21:00 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261065
|
- |
|
guy_bedford
|
live_css
|
Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to e…
|
NVD-CWE-Other
|
CVE-2013-0206
|
2013-03-21 18:26 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261066
|
- |
|
guy_bedford
|
live_css
|
CWE-434: Unrestricted Upload of File with Dangerous Type
|
NVD-CWE-Other
|
CVE-2013-0206
|
2013-03-21 18:26 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261067
|
- |
|
video_project
|
video
|
The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP file.
|
CWE-16
Configuration
|
CVE-2013-0224
|
2013-03-21 13:00 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261068
|
- |
|
user_relationships_project
|
user_relationships
|
Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer us…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0225
|
2013-03-21 13:00 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261069
|
- |
|
mathijs_koenraadt
|
search_api_sorts
|
Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0227
|
2013-03-21 13:00 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261070
|
- |
|
windriver
|
vxworks
|
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a crafted packet.
|
CWE-20
Improper Input Validation
|
CVE-2013-0712
|
2013-03-21 13:00 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|