259731
|
- |
|
cisco
|
identity_services_engine_software
|
Cisco Identity Services Engine (ISE) 1.x before 1.1.1 allows remote attackers to bypass authentication, and read support-bundle configuration and credentials data, via a crafted session on TCP port 4…
|
CWE-287
Improper Authentication
|
CVE-2013-5531
|
2013-10-26 03:57 |
2013-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259732
|
- |
|
cisco
|
ios_xr
|
Cisco IOS XR 3.8.1 through 4.2.0 does not properly process fragmented packets within the RP-A, RP-B, PRP, and DRP-B route-processor components, which allows remote attackers to cause a denial of serv…
|
NVD-CWE-noinfo
|
CVE-2013-5549
|
2013-10-26 03:57 |
2013-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259733
|
- |
|
dhtmlx
|
dhtmlxspreadsheet
|
Cross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6281
|
2013-10-26 03:17 |
2013-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259734
|
- |
|
linksalpha
|
social_sharing_toolkit_plugin
|
Cross-site scripting (XSS) vulnerability in Social Sharing Toolkit plugin before 2.1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6280
|
2013-10-26 03:06 |
2013-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259735
|
- |
|
juniper
|
junos
|
J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 12.2R3, 12.3 before 12.3R2, and 13.1 before 13.1R3 …
|
CWE-352
Origin Validation Error
|
CVE-2013-4689
|
2013-10-26 02:04 |
2013-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259736
|
- |
|
apple
|
iphone_os
|
The Sandbox subsystem in Apple iOS before 7 determines the sandboxing requirement for a #! application on the basis of the script interpreter instead of the script, which allows attackers to bypass i…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5154
|
2013-10-26 01:58 |
2013-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259737
|
- |
|
apple
|
iphone_os
|
The Push Notifications subsystem in Apple iOS before 7 provides the push-notification token to an app without user approval, which allows attackers to obtain sensitive information via an app that emp…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5149
|
2013-10-26 01:56 |
2013-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259738
|
- |
|
apple
|
iphone_os
|
The WifiPasswordController generateDefaultPassword method in Preferences in Apple iOS 6 and earlier relies on the UITextChecker suggestWordInLanguage method for selection of Wi-Fi hotspot WPA2 PSK pa…
|
CWE-255
Credentials Management
|
CVE-2013-4616
|
2013-10-26 01:37 |
2013-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259739
|
- |
|
sap
|
erp_central_component
|
Multiple unspecified vulnerabilities in the CJDB_FILL_MEMORY_FROM_PPB function in the Project System (PS-IS) module for SAP ERP Central Component (ECC) allow remote attackers to execute arbitrary cod…
|
CWE-94
Code Injection
|
CVE-2013-3244
|
2013-10-26 00:18 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259740
|
- |
|
redhat
|
jboss_operations_network
|
The server in Red Hat JBoss Operations Network (JON) 3.1.2 logs passwords in plaintext, which allows local users to obtain sensitive information by reading the log files.
|
CWE-310
Cryptographic Issues
|
CVE-2013-4293
|
2013-10-25 23:33 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|