259471
|
- |
|
cisco
|
ios
|
Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2…
|
CWE-399
Resource Management Errors
|
CVE-2013-5553
|
2013-11-9 02:43 |
2013-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259472
|
- |
|
pineapp
|
mail-secure
|
PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters in a "system ping" command.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4987
|
2013-11-9 02:32 |
2013-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259473
|
- |
|
tattyan
|
tattyan_hptown
|
Cross-site scripting (XSS) vulnerability in Tattyan HP TOWN 5_9_3 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4716
|
2013-11-9 02:09 |
2013-11-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259474
|
- |
|
vmware
|
hyperic_hq
|
The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().exec call.
|
CWE-94
Code Injection
|
CVE-2013-6366
|
2013-11-8 04:47 |
2013-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259475
|
- |
|
wikiwig_project
|
wikiwig
|
Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as used in WikiWig 5.01 and possibly other products, allow remote attackers to in…
|
CWE-79
Cross-site Scripting
|
CVE-2011-5267
|
2013-11-8 04:43 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259476
|
- |
|
saltstack
|
salt
|
Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another rou…
|
CWE-287
Improper Authentication
|
CVE-2013-4435
|
2013-11-8 04:42 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259477
|
- |
|
saltstack
|
salt
|
The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle …
|
CWE-20
Improper Input Validation
|
CVE-2013-4436
|
2013-11-8 04:40 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259478
|
- |
|
saltstack
|
salt
|
Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp."
|
NVD-CWE-noinfo
|
CVE-2013-4437
|
2013-11-8 04:36 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259479
|
- |
|
saltstack
|
salt
|
Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this might not be a vulnerability because the YAML to …
|
CWE-94
Code Injection
|
CVE-2013-4438
|
2013-11-8 04:30 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259480
|
- |
|
adobe
|
coldfusion
|
Unspecified vulnerability in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to read arbitrary files via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2013-3336
|
2013-11-7 13:39 |
2013-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|