260601
|
- |
|
djangoproject canonical
|
django ubuntu_linux
|
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated a…
|
CWE-200
Information Exposure
|
CVE-2013-0305
|
2013-05-15 12:34 |
2013-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260602
|
- |
|
djangoproject canonical
|
django ubuntu_linux
|
Per http://www.ubuntu.com/usn/usn-1757-1/
"A security issue affects these releases of Ubuntu and its derivatives:
Ubuntu 12.10
Ubuntu 12.04 LTS
Ubuntu 11.10
Ubuntu 10.04 LTS"
|
CWE-200
Information Exposure
|
CVE-2013-0305
|
2013-05-15 12:34 |
2013-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260603
|
- |
|
djangoproject canonical
|
django ubuntu_linux
|
The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of ser…
|
CWE-189
Numeric Errors
|
CVE-2013-0306
|
2013-05-15 12:34 |
2013-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260604
|
- |
|
apple
|
cups
|
The cupsFileOpen function in CUPS before 1.4.4 allows local users, with lp group membership, to overwrite arbitrary files via a symlink attack on the (1) /var/cache/cups/remote.cache or (2) /var/cach…
|
CWE-59
Link Following
|
CVE-2010-2431
|
2013-05-15 12:10 |
2010-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260605
|
- |
|
apple
|
cups
|
The cupsDoAuthentication function in auth.c in the client in CUPS before 1.4.4, when HAVE_GSSAPI is omitted, does not properly handle a demand for authorization, which allows remote CUPS servers to c…
|
CWE-399
Resource Management Errors
|
CVE-2010-2432
|
2013-05-15 12:10 |
2010-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260606
|
- |
|
libtiff
|
libtiff
|
The OJPEGReadBufferFill function in tif_ojpeg.c in LibTIFF before 3.9.3 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an OJPEG image with u…
|
NVD-CWE-Other
|
CVE-2010-2443
|
2013-05-15 12:10 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260607
|
- |
|
libtiff
|
libtiff
|
Per: http://cwe.mitre.org/data/definitions/476.html
'CWE-476: NULL Pointer Dereference'
|
NVD-CWE-Other
|
CVE-2010-2443
|
2013-05-15 12:10 |
2010-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260608
|
- |
|
libtiff
|
libtiff
|
The TIFFYCbCrtoRGB function in LibTIFF 3.9.0 and 3.9.2, as used in ImageMagick, does not properly handle invalid ReferenceBlackWhite values, which allows remote attackers to cause a denial of service…
|
CWE-20
Improper Input Validation
|
CVE-2010-2595
|
2013-05-15 12:10 |
2010-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260609
|
- |
|
libtiff
|
libtiff
|
The OJPEGPostDecode function in tif_ojpeg.c in LibTIFF 3.9.0 and 3.9.2, as used in tiff2ps, allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted…
|
CWE-20
Improper Input Validation
|
CVE-2010-2596
|
2013-05-15 12:10 |
2010-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260610
|
- |
|
libtiff
|
libtiff
|
The TIFFVStripSize function in tif_strip.c in LibTIFF 3.9.0 and 3.9.2 makes incorrect calls to the TIFFGetField function, which allows remote attackers to cause a denial of service (application crash…
|
CWE-20
Improper Input Validation
|
CVE-2010-2597
|
2013-05-15 12:10 |
2010-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|