261111
|
- |
|
david_king
|
vino
|
Vino before 2.99.4 can connect external networks contrary to the statement in the vino-preferences dialog box, which might make it easier for remote attackers to perform attacks.
|
CWE-16
Configuration
|
CVE-2011-1164
|
2013-03-19 13:00 |
2013-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261112
|
- |
|
david_king
|
vino
|
Vino, possibly before 3.2, does not properly document that it opens ports in UPnP routers when the "Configure network to automatically accept connections" setting is enabled, which might make it easi…
|
NVD-CWE-Other
|
CVE-2011-1165
|
2013-03-19 13:00 |
2013-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261113
|
- |
|
apple
|
safari
|
WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2013-…
|
NVD-CWE-noinfo
|
CVE-2013-0960
|
2013-03-19 02:06 |
2013-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261114
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended direc…
|
NVD-CWE-noinfo
|
CVE-2013-0966
|
2013-03-19 01:52 |
2013-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261115
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java W…
|
NVD-CWE-noinfo
|
CVE-2013-0967
|
2013-03-19 01:48 |
2013-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261116
|
- |
|
apple
|
mac_os_x
|
Login Window in Apple Mac OS X before 10.8.3 does not prevent application launching with the VoiceOver feature, which allows physically proximate attackers to bypass authentication and make arbitrary…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0969
|
2013-03-19 01:01 |
2013-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261117
|
- |
|
apple
|
mac_os_x mac_os_x_server
|
Use-after-free vulnerability in PDFKit in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted ink annotations i…
|
CWE-399
Resource Management Errors
|
CVE-2013-0971
|
2013-03-19 00:50 |
2013-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261118
|
- |
|
openstack
|
essex folsom
|
(1) installer/basedefs.py and (2) modules/ospluginutils.py in PackStack allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0261
|
2013-03-18 13:00 |
2013-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261119
|
- |
|
openstack
|
essex folsom
|
Per http://rhn.redhat.com/errata/RHSA-2013-0595.html these are the affected products:
Red Hat OpenStack Essex
Red Hat OpenStack Folsom
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0261
|
2013-03-18 13:00 |
2013-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261120
|
- |
|
openstack
|
essex folsom
|
manifests/base.pp in the puppetlabs-cinder module, as used in PackStack, uses world-readable permissions for the (1) cinder.conf and (2) api-paste.ini configuration files, which allows local users to…
|
CWE-362
Race Condition
|
CVE-2013-0266
|
2013-03-18 13:00 |
2013-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|