261251
|
- |
|
rubygems
|
fastreader
|
lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
|
CWE-94
Code Injection
|
CVE-2013-2615
|
2013-03-21 13:00 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261252
|
- |
|
foscam
|
fi8919w
|
Directory traversal vulnerability in the web interface on Foscam devices with firmware before 11.37.2.49 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated…
|
CWE-22
Path Traversal
|
CVE-2013-2560
|
2013-03-20 13:00 |
2013-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261253
|
- |
|
apache
|
qpid
|
The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width elements in the clien…
|
CWE-189
Numeric Errors
|
CVE-2012-4458
|
2013-03-20 01:49 |
2013-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261254
|
- |
|
freeradius
|
freeradius
|
modules/rlm_unix/rlm_unix.c in FreeRADIUS before 2.2.0, when unix mode is enabled for user authentication, does not properly check the password expiration in /etc/shadow, which allows remote authenti…
|
CWE-255
Credentials Management
|
CVE-2011-4966
|
2013-03-19 21:35 |
2013-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261255
|
- |
|
ganglia
|
ganglia-web
|
Multiple cross-site scripting (XSS) vulnerabilities in Ganglia Web before 3.5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-0275
|
2013-03-19 13:00 |
2013-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261256
|
- |
|
fedoraproject
|
389_directory_server
|
389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.
|
CWE-189
Numeric Errors
|
CVE-2013-0312
|
2013-03-19 13:00 |
2013-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261257
|
- |
|
debian
|
cfingerd
|
Buffer overflow in the RFC1413 (ident) client in cfingerd 1.4.3-3 allows remote IDENT servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted response.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-1049
|
2013-03-19 13:00 |
2013-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261258
|
- |
|
piwigo
|
piwigo
|
Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter.
|
CWE-22
Path Traversal
|
CVE-2013-1469
|
2013-03-19 13:00 |
2013-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261259
|
- |
|
apache
|
qpid
|
The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers t…
|
CWE-287
Improper Authentication
|
CVE-2012-4446
|
2013-03-19 13:00 |
2013-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
261260
|
- |
|
apache
|
qpid
|
Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which trigge…
|
CWE-189
Numeric Errors
|
CVE-2012-4459
|
2013-03-19 13:00 |
2013-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|