260401
|
- |
|
openedit_inc
|
openedit
|
Cross-site scripting (XSS) vulnerability in store/search/results.html in OpenEdit 4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) oe-action and (2) page par…
|
NVD-CWE-Other
|
CVE-2005-4476
|
2013-09-12 13:48 |
2005-12-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260402
|
- |
|
realnetworks
|
realplayer realplayer_sp
|
Stack-based buffer overflow in RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted .rmp file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4973
|
2013-09-12 12:37 |
2013-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260403
|
- |
|
realnetworks
|
realplayer realplayer_sp
|
RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed RealM…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4974
|
2013-09-12 12:37 |
2013-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260404
|
- |
|
juniper
|
junos_space junos_space_virtual_appliance junos_space_ja1500_appliance
|
Cross-site scripting (XSS) vulnerability in the web-based interface in Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, allows remote attackers to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5095
|
2013-09-12 12:37 |
2013-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260405
|
- |
|
juniper
|
junos_space junos_space_virtual_appliance junos_space_ja1500_appliance
|
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly implement role-based access control, which allows remote authenticated users to modify th…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5096
|
2013-09-12 12:37 |
2013-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260406
|
- |
|
juniper
|
junos_space junos_space_virtual_appliance junos_space_ja1500_appliance
|
Juniper Junos Space before 13.1R1.6, as used on the JA1500 appliance and in other contexts, does not properly restrict access to the list of user accounts and their MD5 password hashes, which makes i…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5097
|
2013-09-12 12:37 |
2013-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260407
|
- |
|
cisco
|
global_site_selector
|
Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Global Site Selector (GSS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuh42164.
|
CWE-352
Origin Validation Error
|
CVE-2013-5471
|
2013-09-12 12:37 |
2013-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260408
|
- |
|
digium
|
asterisk certified_asterisk
|
The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.17.x through 1.8.22.x, 1.8.23.x before 1.8.23.1, and 11.x before 11.5.1 and Certified Asterisk 1.8.15 before 1.8.15-cert3 and …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5641
|
2013-09-12 12:37 |
2013-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260409
|
- |
|
digium
|
asterisk asterisk_digiumphones certified_asterisk
|
The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.x before 1.8.23.1, 10.x before 10.12.3, and 11.x before 11.5.1; Certified Asterisk 1.8.15 before 1.8.15-cert3 and 11.2 before …
|
CWE-20
Improper Input Validation
|
CVE-2013-5642
|
2013-09-12 12:37 |
2013-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260410
|
- |
|
roundcube
|
webmail
|
Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in …
|
CWE-79
Cross-site Scripting
|
CVE-2013-5645
|
2013-09-12 12:37 |
2013-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|