260331
|
- |
|
advanceprotech
|
advanceware
|
AdvancePro Advanceware allows remote authenticated users to obtain sensitive information about arbitrary customers' orders via a modified id parameter.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3596
|
2013-09-12 12:36 |
2013-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260332
|
- |
|
php
|
php
|
Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (applic…
|
CWE-189
Numeric Errors
|
CVE-2013-4635
|
2013-09-12 12:36 |
2013-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260333
|
- |
|
lockon
|
ec-cube
|
Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKON EC-CUBE 2.12.0 through 2.12.5 on Windows allow remote attackers to read arbit…
|
CWE-22
Path Traversal
|
CVE-2013-4702
|
2013-09-12 12:36 |
2013-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260334
|
- |
|
x
|
libxp
|
Multiple integer overflows in X.org libXp 1.0.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XpGetAttributes, (2) XpGe…
|
CWE-189
Numeric Errors
|
CVE-2013-2062
|
2013-09-12 12:34 |
2013-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260335
|
- |
|
gnome
|
gnome_display_manager
|
GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.
|
CWE-59
Link Following
|
CVE-2013-4169
|
2013-09-12 10:06 |
2013-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260336
|
- |
|
fedoraproject
|
389_directory_server
|
ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request.
|
CWE-20
Improper Input Validation
|
CVE-2013-4283
|
2013-09-11 23:13 |
2013-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260337
|
- |
|
ibm
|
db2
|
IBM DB2 9.1 before FP8 does not require the SETSESSIONUSER privilege for the SET SESSION AUTHORIZATION statement, which has unspecified impact and remote attack vectors.
|
NVD-CWE-noinfo
|
CVE-2009-3473
|
2013-09-11 14:59 |
2009-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260338
|
- |
|
cisco
|
unified_communications_manager
|
Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6a does not properly handle errors, which allows remote attackers to cause a denial of service (service disruption) via malfor…
|
CWE-399
Resource Management Errors
|
CVE-2013-3459
|
2013-09-11 12:23 |
2013-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260339
|
- |
|
searchblox
|
searchblox
|
Directory traversal vulnerability in servlet/CreateTemplateServlet in SearchBlox before 7.5 build 1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the name parameter.
|
CWE-22
Path Traversal
|
CVE-2013-3598
|
2013-09-11 12:23 |
2013-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260340
|
- |
|
oracle
|
fusion_middleware
|
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vec…
|
NVD-CWE-noinfo
|
CVE-2013-3763
|
2013-09-11 12:23 |
2013-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|