260261
|
- |
|
open-xchange
|
open-xchange_appsuite
|
CRLF injection vulnerability in Open-Xchange AppSuite before 7.2.2, when using AJP in certain conditions, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting …
|
CWE-94
Code Injection
|
CVE-2013-6009
|
2013-10-4 23:18 |
2013-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260262
|
- |
|
apache
|
roller
|
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.1 allow remote authenticated users to inject arbitrary web script or HTML by leveraging the blogger role.
|
CWE-79
Cross-site Scripting
|
CVE-2012-2381
|
2013-10-4 04:45 |
2012-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260263
|
- |
|
mozilla
|
bugzilla
|
Bugzilla 4.1.x and 4.2.x before 4.2.2 and 4.3.x before 4.3.2 uses bug-editor privileges instead of bugmail-recipient privileges during construction of HTML bugmail documents, which allows remote atta…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1968
|
2013-10-4 03:50 |
2012-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260264
|
- |
|
piwigo
|
piwigo
|
Cross-site request forgery (CSRF) vulnerability in the LocalFiles Editor plugin in Piwigo before 2.4.7 allows remote attackers to hijack the authentication of administrators for requests that create …
|
CWE-352
Origin Validation Error
|
CVE-2013-1468
|
2013-10-4 03:49 |
2013-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260265
|
- |
|
sophos
|
unified_threat_management_software
|
Unspecified vulnerability in WebAdmin in Sophos UTM (aka Astaro Security Gateway) before 9.105 has unknown impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2013-5932
|
2013-10-4 03:35 |
2013-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260266
|
- |
|
cisco
|
unified_computing_system
|
Absolute path traversal vulnerability in the image-download process in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to overwrite or delete arbitrary fi…
|
CWE-22
Path Traversal
|
CVE-2012-4104
|
2013-10-4 03:32 |
2013-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260267
|
- |
|
joomla
|
joomla\!
|
Joomla! 2.5.x before 2.5.4 does not properly check permissions, which allows attackers to obtain sensitive "administrative back end" information via unknown attack vectors. NOTE: this might be a dup…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-1611
|
2013-10-4 03:31 |
2012-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260268
|
- |
|
cisco
|
unified_computing_system
|
run-script in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq86560.
|
CWE-20
Improper Input Validation
|
CVE-2012-4110
|
2013-10-4 03:31 |
2013-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260269
|
- |
|
progea
|
movicon
|
The OPC server in Progea Movicon before 11.3 allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted HTTP request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-1804
|
2013-10-4 03:30 |
2012-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260270
|
- |
|
enea emerson
|
ose roc_800l_remote_terminal_unit roc_800_remote_terminal_unit dl_8000_remote_terminal_unit
|
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows re…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0692
|
2013-10-4 03:07 |
2013-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|