260061
|
- |
|
samsung
|
shr-5082 shr-5162
|
Cross-site scripting (XSS) vulnerability in Samsung SHR-5162, SHR-5082, and possibly other models, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3964
|
2013-10-3 02:10 |
2013-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260062
|
- |
|
emc
|
geosynchrony vplex_geo vplex_local vplex_metro
|
EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local users to obtain sensitive information by reading the management-server configur…
|
CWE-255
Credentials Management
|
CVE-2013-3278
|
2013-10-3 00:16 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260063
|
- |
|
wordpress
|
wordpress
|
wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP u…
|
CWE-94
Code Injection
|
CVE-2013-4338
|
2013-10-2 13:29 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260064
|
- |
|
wordpress
|
wordpress
|
wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4340
|
2013-10-2 13:29 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260065
|
- |
|
canonical
|
ubuntu_linux
|
A certain Ubuntu build procedure for perf, as distributed in the Linux kernel packages in Ubuntu 10.04 LTS, 12.04 LTS, 12.10, 13.04, and 13.10, sets the HOME environment variable to the ~buildd direc…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1060
|
2013-10-2 13:23 |
2013-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260066
|
- |
|
rockwellautomation
|
rslinx_enterprise
|
Buffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-4715
|
2013-10-2 13:18 |
2013-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260067
|
- |
|
x2engine
|
x2crm
|
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to inde…
|
CWE-22
Path Traversal
|
CVE-2013-5692
|
2013-10-2 05:01 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260068
|
- |
|
cisco
|
unified_computing_system
|
The local file editor in the Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and modify arbitrary fabric-interconnect files, in the…
|
CWE-20
Improper Input Validation
|
CVE-2012-4096
|
2013-10-2 04:23 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260069
|
- |
|
argosoft
|
argosoft_mail_server
|
ArGoSoft Mail Server 1.8.1.7 and earlier allows a webmail user to cause a denial of service (CPU consumption) by forwarding the email to the user while autoresponse is enabled, which creates an infin…
|
NVD-CWE-Other
|
CVE-2002-1005
|
2013-10-1 10:22 |
2002-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260070
|
- |
|
vmware
|
esx esxi
|
VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to cause a denial of service (unhandled ex…
|
CWE-20
Improper Input Validation
|
CVE-2013-1661
|
2013-09-30 23:35 |
2013-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|