259761
|
- |
|
canonical
|
ubuntu_linux
|
X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.
|
NVD-CWE-noinfo
|
CVE-2013-1056
|
2013-10-29 23:18 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259762
|
- |
|
polarssl
|
polarssl
|
Buffer overflow in the ssl_read_record function in ssl_tls.c in PolarSSL before 1.1.8, when using TLS 1.1, might allow remote attackers to execute arbitrary code via a long packet.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5914
|
2013-10-29 00:46 |
2013-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259763
|
- |
|
binarymoon
|
timthumb
|
TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-list…
|
CWE-20
Improper Input Validation
|
CVE-2011-4106
|
2013-10-29 00:15 |
2013-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259764
|
- |
|
dlitz
|
pycrypto
|
The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for c…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1445
|
2013-10-29 00:14 |
2013-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259765
|
- |
|
sap
|
erp_central_component
|
Unspecified vulnerability in the Statutory Reporting for Insurance (FS_SR) component in the Financial Services module for SAP ERP Central Component (ECC) allows attackers to execute arbitrary code vi…
|
NVD-CWE-noinfo
|
CVE-2013-6284
|
2013-10-29 00:03 |
2013-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259766
|
- |
|
canonical
|
ubuntu_linux
|
Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by reading the file.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1067
|
2013-10-28 22:49 |
2013-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259767
|
- |
|
wellintech
|
kingview
|
The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveToFile method calls, which allows remote attackers …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6128
|
2013-10-28 22:39 |
2013-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259768
|
- |
|
wellintech
|
kingview
|
The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict ReplaceDBFile method calls, which allows remote atta…
|
CWE-22
Path Traversal
|
CVE-2013-6127
|
2013-10-28 22:32 |
2013-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259769
|
- |
|
emc
|
rsa_authentication_agent
|
EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which allows remote attackers to bypass intended access restrictions via vectors that…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3280
|
2013-10-26 04:00 |
2013-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259770
|
- |
|
cisco
|
identity_services_engine_software
|
Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers to cause a denial of service (exhaustion of the account supply) via a series of…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5521
|
2013-10-26 04:00 |
2013-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|