260851
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
SMB in Apple Mac OS X before 10.8.4, when file sharing is enabled, allows remote authenticated users to create or modify files outside of a shared directory via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0990
|
2013-06-5 23:39 |
2013-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260852
|
- |
|
apple
|
safari
|
XSS Auditor in WebKit in Apple Safari before 6.0.5 does not properly rewrite URLs, which allows remote attackers to trigger unintended form submissions via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2013-1013
|
2013-06-5 23:39 |
2013-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260853
|
- |
|
apple
|
safari
|
WebKit, as used in Apple Safari before 6.0.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a differ…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-1023
|
2013-06-5 23:39 |
2013-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260854
|
- |
|
apple
|
mac_os_x
|
The posix_spawn system call in the XNU kernel in Apple Mac OS X 10.8.x does not prevent use of the _POSIX_SPAWN_DISABLE_ASLR and _POSIX_SPAWN_ALLOW_DATA_EXEC flags for setuid and setgid programs, whi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3949
|
2013-06-5 23:39 |
2013-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260855
|
- |
|
apple
|
mac_os_x
|
IOAcceleratorFamily in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted graphics image.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-0976
|
2013-06-5 13:00 |
2013-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260856
|
- |
|
typo3
|
typo3
|
SQL injection vulnerability in the Extbase Framework in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to execute arbitrary SQL com…
|
CWE-89
SQL Injection
|
CVE-2013-1842
|
2013-06-5 12:42 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260857
|
- |
|
typo3
|
typo3
|
Open redirect vulnerability in the Access tracking mechanism in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to redirect users to…
|
CWE-399
Resource Management Errors
|
CVE-2013-1843
|
2013-06-5 12:42 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260858
|
- |
|
mozilla
|
firefox
|
Unspecified vulnerability in the browser engine in Mozilla Firefox before 20.0 on Android allows remote attackers to cause a denial of service (stack memory corruption and application crash) or possi…
|
NVD-CWE-noinfo
|
CVE-2013-0790
|
2013-06-5 12:41 |
2013-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260859
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox before 20.0 on Android uses world-writable and world-readable permissions for the app_tmp installation directory in the local filesystem, which allows attackers to modify add-ons befo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0798
|
2013-06-5 12:41 |
2013-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260860
|
- |
|
openstack canonical
|
essex folsom grizzly ubuntu_linux
|
OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) allows remote authenticated users to gain access to a VM in opportunistic circumstances by using the VNC token for a deleted VM t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0335
|
2013-06-5 12:40 |
2013-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|