Unknown · CVSS Not scored
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3912.
Published Nov 13, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Published Nov 13, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to cause a denial of service (daemon hang) via a web-service request containing a crafted X.509 certificate that is not properly handled during validation, aka "Digital Signatures Vulnerability."
Published Nov 13, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (Apache::Session::File) and certain authentication extensions, allows remote attackers to reuse unauthorized sessions and obtain user preferences and caches via unspecified vectors.
Published Nov 16, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
evince is missing a check on number of pages which can lead to a segmentation fault
Published Nov 1, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple unspecified vulnerabilities in SAP Governance, Risk, and Compliance (GRC) allow remote authenticated users to gain privileges and execute arbitrary programs via a crafted (1) RFC or (2) SOAP-RFC request.
Published Nov 17, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.
Published Nov 1, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.
Published Nov 13, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.
Published Nov 13, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the web interface in Cisco Prime Network Registrar 8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted field, aka Bug ID CSCuh41429.
Published Nov 27, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Loftek Nexus 543 IP Camera allows remote attackers to obtain (1) IP addresses via a request to get_realip.cgi or (2) firmware versions (ui and system), timestamp, serial number, p2p port number, and wifi status via a request to get_status.cgi.
Published Nov 21, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.
Published Nov 13, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.
Published Nov 13, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) passwords or (2) firewall configuration, as demonstrated by a request to set_users.cgi.
Published Nov 21, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7 SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital Asset Manager before 6.5 SP6, Documentum Administrator before 6.7 SP2 P07, and Documentum Capital Projects before 1.8 P01 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter in a URL.
Published Nov 6, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in the Loftek Nexus 543 IP Camera allows remote attackers to read arbitrary files via a .. (dot dot) in the URL of an HTTP GET request.
Published Nov 21, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability on the EMC RSA Data Protection Manager (DPM) appliance 3.2.x before 3.2.4.2 and 3.5.x before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
Published Nov 22, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive information via an HTTP GET request to check_users.cgi. NOTE: cleartext passwords can also be obtained from proc/kcore when leveraging the directory traversal vulnerability in CVE-2013-3311.
Published Nov 21, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of chat messages, or compose anonymous chat messages, by leveraging meeting-attendance privileges.
Published Nov 9, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to share crafted links via the Library function.
Published Nov 9, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Unspecified Cross-site scripting (XSS) vulnerability in the Verizon FIOS Actiontec MI424WR-GEN3I router.
Published Nov 13, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A Symlink Traversal vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34.
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An Information Disclosure vulnerability exists in Netgear WNDR4700 running firmware 1.0.0.34 in the management web interface, which discloses the PSK of the wireless LAN.
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An Authentication Bypass vulnerability exists in NETGEAR Centria WNDR4700 Firmware 1.0.0.34 in http://<router_ip>/apply.cgi?/hdd_usr_setup.htm that when visited by any user, authenticated or not, causes the router to no longer require a password to access the web administration portal.
Published Nov 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote attackers to cause a denial of service (temporary gateway outage) via crafted HTTP requests.
Published Nov 16, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet.
Published Nov 22, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.48 allow attackers to execute arbitrary code or possibly have other impact via unknown vectors.
Published Nov 13, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.
Published Nov 22, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
minidlna has SQL Injection that may allow retrieval of arbitrary files
Published Nov 1, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
MiniDLNA has heap-based buffer overflow
Published Nov 1, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.
Published Nov 2, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
Published Nov 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
MiniUPnPd has information disclosure use of snprintf()
Published Nov 1, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.
Published Nov 23, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
HTTPSConnections in OpenStack Keystone 2013, OpenStack Compute 2013.1, and possibly other OpenStack components, fail to validate server-side SSL certificates.
Published Nov 1, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
Published Nov 4, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cryptocat before 2.0.42 has Group Chat ECC Private Key Generation Brute Force Weakness
Published Nov 4, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cryptocat strophe.js before 2.0.22 has information disclosure
Published Nov 4, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
vzkernel before 042stab080.2 in the OpenVZ modification for the Linux kernel 2.6.32 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via (1) a crafted ploop driver ioctl call, related to the ploop_getdevice_ioc function in drivers/block/ploop/dev.c, or (2) a crafted quotactl system call, related to the compat_quotactl function in fs/quota/quota.c.
Published Nov 12, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
Published Nov 4, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cryptocat before 2.0.22: Cryptocat.random() Function Array Key has Entropy Weakness
Published Nov 4, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
Published Nov 1, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cryptocat before 2.0.22 has Nickname User Impersonation
Published Nov 4, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.
Published Nov 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.
Published Nov 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
Published Nov 20, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
nagios.upgrade_to_v3.sh, as distributed by Red Hat and possibly others for Nagios Core 3.4.4, 3.5.1, and earlier, allows local users to overwrite arbitrary files via a symlink attack on a temporary nagioscfg file with a predictable name in /tmp/.
Published Nov 23, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
MediaWiki before 1.19.6 and 1.20.x before 1.20.5 allows remote attackers to conduct cross-site scripting (XSS) attacks, as demonstrated by a CDATA section containing valid UTF-7 encoded sequences in a SVG file, which is then incorrectly interpreted as UTF-8 by Chrome and Firefox.
Published Nov 15, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service (system crash) by sending a large amount of network traffic through a USB/Ethernet adapter.
Published Nov 4, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The openvpn_decrypt function in crypto.c in OpenVPN 2.3.0 and earlier, when running in UDP mode, allows remote attackers to obtain sensitive information via a timing attack involving an HMAC comparison function that does not run in constant time and a padding oracle attack on the CBC mode cipher.
Published Nov 15, 2013 · Updated Aug 6, 2024