259551
|
- |
|
triplc
|
nano-10_plc_firmware nano-10_plc
|
Triangle Research International (aka Tri) Nano-10 PLC devices with firmware r81 and earlier do not properly handle large length values in MODBUS data, which allows remote attackers to cause a denial …
|
CWE-20
Improper Input Validation
|
CVE-2013-5741
|
2013-10-30 05:56 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259552
|
- |
|
aircrack-ng gentoo
|
aircrack-ng linux
|
Multiple heap-based buffer overflows in Aircrack-ng before 1.1 allow remote attackers to cause a denial of service (crash) and execute arbitrary code via a (1) large length value in an EAPOL packet o…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2010-1159
|
2013-10-30 05:53 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259553
|
- |
|
novell
|
libzypp
|
The RPM GPG key import and handling feature in libzypp 12.15.0 and earlier reports a different key fingerprint than the one used to sign a repository when multiple key blobs are used, which might all…
|
CWE-310
Cryptographic Issues
|
CVE-2013-3704
|
2013-10-30 01:08 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259554
|
- |
|
drupal
|
drupal
|
The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields vi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-0827
|
2013-10-30 00:19 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259555
|
- |
|
canonical
|
ubuntu_linux
|
X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.
|
NVD-CWE-noinfo
|
CVE-2013-1056
|
2013-10-29 23:18 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259556
|
- |
|
polarssl
|
polarssl
|
Buffer overflow in the ssl_read_record function in ssl_tls.c in PolarSSL before 1.1.8, when using TLS 1.1, might allow remote attackers to execute arbitrary code via a long packet.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5914
|
2013-10-29 00:46 |
2013-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259557
|
- |
|
binarymoon
|
timthumb
|
TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote attackers to upload and execute arbitrary code via a URL containing a white-list…
|
CWE-20
Improper Input Validation
|
CVE-2011-4106
|
2013-10-29 00:15 |
2013-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259558
|
- |
|
dlitz
|
pycrypto
|
The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for c…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1445
|
2013-10-29 00:14 |
2013-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259559
|
- |
|
sap
|
erp_central_component
|
Unspecified vulnerability in the Statutory Reporting for Insurance (FS_SR) component in the Financial Services module for SAP ERP Central Component (ECC) allows attackers to execute arbitrary code vi…
|
NVD-CWE-noinfo
|
CVE-2013-6284
|
2013-10-29 00:03 |
2013-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259560
|
- |
|
canonical
|
ubuntu_linux
|
Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by reading the file.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1067
|
2013-10-28 22:49 |
2013-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|