260371
|
- |
|
cisco
|
nx-os
|
Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communication, which allows remote attackers to obtain VEM …
|
CWE-287
Improper Authentication
|
CVE-2013-1211
|
2013-05-30 22:43 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260372
|
- |
|
cisco
|
nx-os
|
Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, when STUN debugging is enabled, allows remote attackers to cause a denial of se…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-1210
|
2013-05-30 22:36 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260373
|
- |
|
cisco
|
nx-os
|
The encryption functionality in the Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication component in Cisco NX-OS on the Nexus 1000V does not properly authenticate VSM/VEM p…
|
CWE-287
Improper Authentication
|
CVE-2013-1209
|
2013-05-30 22:30 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260374
|
- |
|
cisco
|
nx-os
|
The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication, which allows remote attackers t…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1208
|
2013-05-30 22:26 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260375
|
- |
|
lockon
|
ec-cube
|
Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2312
|
2013-05-30 13:00 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260376
|
- |
|
lockon
|
ec-cube
|
data/class/pages/forgot/LC_Page_Forgot.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 does not properly validate the input to the password reminder function, which allows remote attackers to obtain …
|
CWE-20
Improper Input Validation
|
CVE-2013-2315
|
2013-05-30 13:00 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260377
|
- |
|
gentoo
|
webmin
|
Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.
|
CWE-20
Improper Input Validation
|
CVE-2012-2981
|
2013-05-30 12:16 |
2012-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260378
|
- |
|
gentoo
|
webmin
|
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
|
NVD-CWE-Other
|
CVE-2012-2982
|
2013-05-30 12:16 |
2012-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260379
|
- |
|
gentoo
|
webmin
|
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file fi…
|
CWE-287
Improper Authentication
|
CVE-2012-2983
|
2013-05-30 12:16 |
2012-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260380
|
- |
|
ibm
|
infosphere_optim_data_growth_for_oracle_e-business_suite
|
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 relies on the MD5 algorithm for signatures in X.509 certificates, which makes it easier for man-in-the-mi…
|
CWE-310
Cryptographic Issues
|
CVE-2013-2953
|
2013-05-28 13:00 |
2013-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|