258961
|
- |
|
adobe
|
shockwave_player
|
Adobe Shockwave Player before 12.0.7.148 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5334
|
2013-12-13 03:44 |
2013-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258962
|
- |
|
adobe
|
shockwave_player
|
Adobe Shockwave Player before 12.0.7.148 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5333
|
2013-12-13 03:43 |
2013-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258963
|
- |
|
siemens
|
comos
|
Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local users to gain database privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6840
|
2013-12-13 02:11 |
2013-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258964
|
- |
|
siemens
|
comos
|
Per: https://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-568732.pdf
AC:M for "Mitigating factors:
The attacker must have local access to the system as authentic…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6840
|
2013-12-13 02:11 |
2013-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258965
|
- |
|
cisco
|
scientific_atlanta_dpc\/epc2100 scientific_atlanta_dpc\/epc2202 scientific_atlanta_dpc\/epc2203 scientific_atlanta_dpc\/epc2325 scientific_atlanta_dpc\/epc2425 scientific_atlanta_dpc\/…
|
Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecifi…
|
CWE-79
Cross-site Scripting
|
CVE-2012-3047
|
2013-12-13 01:56 |
2013-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258966
|
- |
|
novell
|
suse_lifecycle_management_server
|
SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms b…
|
CWE-310
Cryptographic Issues
|
CVE-2013-3710
|
2013-12-13 00:18 |
2013-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258967
|
- |
|
enorth
|
webpublisher_cms
|
SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows remote attackers to execute arbitrary SQL commands via the thisday parameter.
|
CWE-89
SQL Injection
|
CVE-2013-6985
|
2013-12-12 04:22 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258968
|
- |
|
cmsmadesimple
|
cms_made_simple
|
Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the "Modify Events" permission to inject arbitrary web script …
|
CWE-79
Cross-site Scripting
|
CVE-2013-3929
|
2013-12-11 06:14 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258969
|
- |
|
ffmpeg
|
ffmpeg
|
Buffer overflow in FFmpeg before 0.5.6, 0.6.x before 0.6.4, 0.7.x before 0.7.8, and 0.8.x before 0.8.8 allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2011-4351
|
2013-12-11 02:04 |
2013-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258970
|
- |
|
djangoproject
|
django
|
Directory traversal vulnerability in Django 1.4.x before 1.4.7, 1.5.x before 1.5.3, and 1.6.x before 1.6 beta 3 allows remote attackers to read arbitrary files via a file path in the ALLOWED_INCLUDE_…
|
CWE-22
Path Traversal
|
CVE-2013-4315
|
2013-12-10 15:05 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|