258601
|
- |
|
xnview
|
xnview
|
Integer overflow in xnview.exe in XnView 2.13 allows remote attackers to execute arbitrary code via a large NUM_ELEMENTS field in an IFD_ENTRY structure in a JXR file, which triggers a heap-based buf…
|
CWE-189
Numeric Errors
|
CVE-2013-3938
|
2014-03-19 22:59 |
2014-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258602
|
- |
|
sophos
|
web_appliance_firmware web_appliance
|
Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter in an allow action t…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2643
|
2014-03-19 22:55 |
2014-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258603
|
- |
|
sophos
|
web_appliance_firmware web_appliance
|
Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation va…
|
CWE-78
OS Command
|
CVE-2013-2642
|
2014-03-19 22:54 |
2014-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258604
|
- |
|
sophos
|
web_appliance_firmware web_appliance
|
Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.
|
CWE-22
Path Traversal
|
CVE-2013-2641
|
2014-03-19 22:48 |
2014-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258605
|
- |
|
yumenomachi
|
demaecan
|
The Demaecan application 2.1.0 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information …
|
CWE-310
Cryptographic Issues
|
CVE-2014-1976
|
2014-03-19 01:05 |
2014-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258606
|
- |
|
owncloud
|
owncloud
|
The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an unspecified JavaScript file.
|
CWE-200
Information Exposure
|
CVE-2013-2086
|
2014-03-18 00:43 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258607
|
- |
|
owncloud
|
owncloud
|
The login page (aka index.php) in ownCloud before 5.0.6 does not disable the autocomplete setting for the password parameter, which makes it easier for physically proximate attackers to guess the pas…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2047
|
2014-03-18 00:37 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258608
|
- |
|
owncloud
|
owncloud
|
Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the …
|
NVD-CWE-Other
|
CVE-2013-2089
|
2014-03-18 00:36 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258609
|
- |
|
owncloud
|
owncloud
|
Per: https://cwe.mitre.org/data/definitions/184.html
"CWE-184: Incomplete Blacklist"
|
NVD-CWE-Other
|
CVE-2013-2089
|
2014-03-18 00:36 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258610
|
- |
|
owncloud
|
owncloud
|
ownCloud before 5.0.6 does not properly check permissions, which allows remote authenticated users to execute arbitrary API commands via unspecified vectors. NOTE: this can be leveraged using CSRF t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2048
|
2014-03-18 00:26 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|