260201
|
- |
|
baramundi
|
management_suite
|
Baramundi Management Suite 7.5 through 8.9 uses cleartext for (1) client-server communication and (2) data storage, which allows remote attackers to obtain sensitive information by sniffing the netwo…
|
CWE-310
Cryptographic Issues
|
CVE-2013-3593
|
2013-10-4 00:25 |
2013-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260202
|
- |
|
cisco
|
unified_computing_system
|
The activate firmware command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka…
|
CWE-20
Improper Input Validation
|
CVE-2012-4102
|
2013-10-3 23:48 |
2013-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260203
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by usin…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1727
|
2013-10-3 12:38 |
2013-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260204
|
- |
|
mozilla
|
firefox
|
The WebGL implementation in Mozilla Firefox before 24.0, when NVIDIA graphics drivers are used on Mac OS X, allows remote attackers to obtain desktop-screenshot data by reading from a CANVAS element.
|
CWE-200
Information Exposure
|
CVE-2013-1729
|
2013-10-3 12:38 |
2013-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260205
|
- |
|
mozilla
|
firefox
|
Untrusted search path vulnerability in the GL tracing functionality in Mozilla Firefox before 24.0 on Android allows attackers to execute arbitrary code via a Trojan horse .so file in a world-writabl…
|
CWE-20
Improper Input Validation
|
CVE-2013-1731
|
2013-10-3 12:38 |
2013-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260206
|
- |
|
mongodb
|
mongodb
|
The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possi…
|
CWE-399
Resource Management Errors
|
CVE-2013-3969
|
2013-10-3 05:38 |
2013-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260207
|
- |
|
cisco
|
mediasense
|
Cross-site scripting (XSS) vulnerability in the oraservice page in Cisco MediaSense allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuj23328.
|
CWE-79
Cross-site Scripting
|
CVE-2013-5501
|
2013-10-3 04:44 |
2013-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260208
|
- |
|
cisco
|
mediasense
|
Multiple cross-site scripting (XSS) vulnerabilities in the oraadmin service page in Cisco MediaSense allow remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bu…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5500
|
2013-10-3 04:43 |
2013-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260209
|
- |
|
ovislink sony
|
airlive_wl2600cam snc_ch140 snc_ch180 snc_ch240 snc_ch280 snc_dh140 snc_dh140t snc_dh180 snc_dh240 snc_dh240t snc_dh280
|
Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and pos…
|
CWE-352
Origin Validation Error
|
CVE-2013-3539
|
2013-10-3 04:26 |
2013-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260210
|
- |
|
grandstream
|
gxv_device_firmware gxv3500 gxv3501 gxv3504 gxv3601 gxv3601hd\/ll gxv3611hd\/ll gxv3615w\/p gxv3615wp_hd gxv3651fhd gxv3662hd
|
Cross-site scripting (XSS) vulnerability in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera mode…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3962
|
2013-10-3 02:28 |
2013-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|