261111
|
- |
|
zugec_ivan
|
keyboard_shortcut_utility
|
The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal does not properly check node restrictions, which allows (1) remote authenticated users with the "view shortcuts" permission to r…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0226
|
2013-03-21 23:45 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261112
|
- |
|
leighton_whiting
|
mark_complete
|
Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown v…
|
CWE-352
Origin Validation Error
|
CVE-2013-0207
|
2013-03-21 23:21 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261113
|
- |
|
debian
|
latd
|
Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long strin…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-0251
|
2013-03-21 21:00 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261114
|
- |
|
guy_bedford
|
live_css
|
Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to e…
|
NVD-CWE-Other
|
CVE-2013-0206
|
2013-03-21 18:26 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261115
|
- |
|
guy_bedford
|
live_css
|
CWE-434: Unrestricted Upload of File with Dangerous Type
|
NVD-CWE-Other
|
CVE-2013-0206
|
2013-03-21 18:26 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261116
|
- |
|
video_project
|
video
|
The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP file.
|
CWE-16
Configuration
|
CVE-2013-0224
|
2013-03-21 13:00 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261117
|
- |
|
user_relationships_project
|
user_relationships
|
Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer us…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0225
|
2013-03-21 13:00 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261118
|
- |
|
mathijs_koenraadt
|
search_api_sorts
|
Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML v…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0227
|
2013-03-21 13:00 |
2013-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261119
|
- |
|
windriver
|
vxworks
|
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a crafted packet.
|
CWE-20
Improper Input Validation
|
CVE-2013-0712
|
2013-03-21 13:00 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261120
|
- |
|
nec
|
atermwm3450rn atermwm3600r atermwr8160n atermwr8370n atermwr8600n atermwr9500n
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN route…
|
CWE-352
Origin Validation Error
|
CVE-2013-0717
|
2013-03-21 13:00 |
2013-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|