258241
|
- |
|
google
|
android
|
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within mu…
|
CWE-200
Information Exposure
|
CVE-2013-7373
|
2014-04-30 21:57 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258242
|
- |
|
simplemachines
|
simple_machines_forum
|
Simple Machines Forum (SMF) 2.0.6, 1.1.19, and earlier allows remote attackers to impersonate arbitrary users via a Unicode homoglyph character in a username.
|
CWE-20
Improper Input Validation
|
CVE-2013-7236
|
2014-04-30 20:21 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258243
|
- |
|
gnome
|
gnome-shell
|
The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute ar…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7221
|
2014-04-30 04:03 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258244
|
- |
|
gnome
|
gnome-shell
|
js/ui/screenShield.js in GNOME Shell (aka gnome-shell) before 3.8 allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation with the keyboard focus o…
|
NVD-CWE-Other
|
CVE-2013-7220
|
2014-04-30 03:53 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258245
|
- |
|
gnome
|
gnome-shell
|
Per: https://cwe.mitre.org/data/definitions/77.html
"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')"
|
NVD-CWE-Other
|
CVE-2013-7220
|
2014-04-30 03:53 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258246
|
- |
|
phusion
|
juvia
|
Juvia uses the same secret key for all installations, which allows remote attackers to have unspecified impact by leveraging the secret key in app/config/initializers/secret_token.rb, related to cook…
|
CWE-255
Credentials Management
|
CVE-2013-7134
|
2014-04-30 03:13 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258247
|
- |
|
basespace_ruby_sdk_project
|
basespace_ruby_sdk
|
The put_call function in the API client (api/api_client.rb) in the BaseSpace Ruby SDK (aka bio-basespace-sdk) gem 0.1.7 for Ruby uses the API_KEY on the command line, which allows remote attackers to…
|
CWE-200
Information Exposure
|
CVE-2013-7111
|
2014-04-30 02:59 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258248
|
- |
|
organic_groups_project
|
organic_groups
|
The Organic Groups (OG) module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users to bypass group restrictions on nodes with all groups set to optional input via an empty group field.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7068
|
2014-04-30 02:52 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258249
|
- |
|
entity_reference_project
|
entityreference
|
The Entity reference module 7.x-1.x before 7.x-1.1-rc1 for Drupal allows remote attackers to read private nodes titles by leveraging edit permissions to a node that references a private node.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7066
|
2014-04-30 02:45 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258250
|
- |
|
freelance-it-consultant
|
eu_cookie_compliance
|
Cross-site scripting (XSS) vulnerability in the EU Cookie Compliance module 7.x-1.x before 7.x-1.12 for Drupal allows remote authenticated administrators with the "Administer EU Cookie Compliance pop…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7064
|
2014-04-30 02:09 |
2014-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|