259971
|
- |
|
htmlcleaner_project open-xchange
|
htmlcleaner open-xchange_appsuite
|
Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other person…
|
CWE-362
Race Condition
|
CVE-2013-5035
|
2013-10-9 02:33 |
2013-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259972
|
- |
|
htmlcleaner_project open-xchange
|
htmlcleaner open-xchange_appsuite
|
CVSS score reflects vendor comments provided in http://archives.neohapsis.com/archives/bugtraq/2013-08/0115.html
|
CWE-362
Race Condition
|
CVE-2013-5035
|
2013-10-9 02:33 |
2013-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259973
|
- |
|
trianglemicroworks
|
ansi_c_source_code_libraries .net_communication_protocol_components scada_data_gateway
|
Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow physically prox…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-2794
|
2013-10-9 02:24 |
2013-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259974
|
- |
|
chamanet
|
chamacargo
|
Cross-site scripting (XSS) vulnerability in ChamaNet ChamaCargo 7.0000 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4704
|
2013-10-9 01:23 |
2013-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259975
|
- |
|
gomlab
|
gom_player
|
Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.
|
CWE-20
Improper Input Validation
|
CVE-2013-5716
|
2013-10-9 01:04 |
2013-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259976
|
- |
|
gomlab
|
gom_player
|
Buffer overflow in Gretech GOM Media Player before 2.2.53.5169 has unspecified impact and attack vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5715
|
2013-10-9 00:51 |
2013-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259977
|
- |
|
marketpress
|
backwpup_plugin
|
Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter to wp-admin/admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4626
|
2013-10-8 23:22 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259978
|
- |
|
apple
|
iphone_os
|
Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by making a series of…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5160
|
2013-10-8 06:04 |
2013-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259979
|
- |
|
apple
|
iphone_os
|
Passcode Lock in Apple iOS before 7.0.2 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement, and open the Camera app or rea…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5161
|
2013-10-8 05:53 |
2013-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259980
|
- |
|
cisco
|
ios
|
The PPTP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via crafted TCP port-1723 packets, aka Bug ID C…
|
CWE-20
Improper Input Validation
|
CVE-2013-5481
|
2013-10-8 05:36 |
2013-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|