Unknown · CVSS Not scored
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-5047.
Published Dec 11, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-5048.
Published Dec 11, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."
Published Dec 11, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
Published Dec 11, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in RockMongo 1.1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ROCK_LANG cookie, as demonstrated in a login.index action to index.php.
Published Dec 14, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCount value in an ICONDIR structure in an ICO file. NOTE: some of these details are obtained from third party information.
Published Dec 13, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Microsoft Office 2013 and 2013 RT allows remote attackers to discover authentication tokens via a crafted response to a file-open request for an Office file on a web site, as exploited in the wild in 2013, aka "Token Hijacking Vulnerability."
Published Dec 11, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in Microsoft ASP.NET SignalR 1.1.x before 1.1.4 and 2.0.x before 2.0.1, and Visual Studio Team Foundation Server 2013, allows remote attackers to inject arbitrary web script or HTML via crafted Forever Frame transport protocol data, aka "SignalR XSS Vulnerability."
Published Dec 11, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges via a crafted application, aka "Win32k Integer Overflow Vulnerability."
Published Dec 11, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages.
Published Dec 30, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.
Published Dec 30, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Collabtive 1.0 has incorrect access control
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Hikvision DS-2CD7153-E IP Camera has Privilege Escalation
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
AVTECH AVN801 DVR has a security bypass via the administration login captcha
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
INSTEON Hub 2242-222 lacks Web and API authentication
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspecified vectors related to "live management."
Published Dec 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Karotz API 12.07.19.00: Session Token Information Disclosure
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav.
Published Dec 30, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability on HP Officejet Pro 8500 (aka A909) All-in-One printers allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published Dec 14, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ReviewBoard 1.6.17 allows code execution by attaching PHP scripts to review request
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Owl Intranet Knowledgebase 1.10 allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search field to browse.php or (2) the Title field to prefs.php.
Published Dec 26, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SPBAS Business Automation Software 2012 has XSS.
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The update function in umbraco.webservices/templates/templateService.cs in the TemplateService component in Umbraco CMS before 6.0.4 does not require authentication, which allows remote attackers to execute arbitrary ASP.NET code via a crafted SOAP request.
Published Dec 27, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.11.9 and earlier allow remote authenticated users to inject arbitrary web script or HTML via (1) the Search field in an inbox action to messaging/messagebox.php, (2) the "First name" field to auth/profile.php, or (3) the Speakers field in an rqAdd action to calendar/agenda.php.
Published Dec 26, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Static HTTP Server 1.0 has a Local Overflow
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier, GS748Tv4 5.4.1.14, and GS510TP 5.0.4.4 allows remote attackers to cause a denial of service (reboot or crash) via a crafted HTTP request to filesystem/.
Published Dec 19, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Samsung Galaxy S3/S4 exposes an unprotected component allowing an unprivileged app to send arbitrary SMS texts to arbitrary destinations without permission.
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Samsung Galaxy S3/S4 exposes an unprotected component allowing arbitrary SMS text messages without requesting permission.
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The cloud controller (aka CLC) component in Eucalyptus 3.3.x and 3.4.x before 3.4.2, when the dns.recursive.enabled setting is used, allows remote attackers to cause a denial of service (traffic amplification) via spoofed DNS queries.
Published Dec 26, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote attackers to read encrypted administrator credentials and other startup configurations via a direct request to filesystem/startup-config.
Published Dec 19, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
git_http_controller.rb in the redmine_git_hosting plugin for Redmine allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the service parameter to info/refs, related to the get_info_refs function or (2) the reqfile argument to the file_exists function.
Published Dec 28, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WordPress Xorbin Digital Flash Clock 1.0 has XSS
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Sencha Labs Connect has XSS with connect.methodOverride()
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
SPBAS Business Automation Software 2012 has CSRF.
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Magnolia CMS before 4.5.9 has multiple access bypass vulnerabilities
Published Dec 27, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.
Published Dec 14, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.
Published Dec 12, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2.
Published Dec 24, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
jarsigner in OpenJDK and Oracle Java SE before 7u51 allows remote attackers to bypass a code-signing protection mechanism and inject unsigned bytecode into a signed JAR file by leveraging improper file validation.
Published Dec 29, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.
Published Dec 7, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
RubyGem omniauth-facebook has an access token security vulnerability
Published Dec 11, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.
Published Dec 7, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration files, which allows local users to obtain authentication credentials and other unspecified sensitive information by reading these files.
Published Dec 24, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a \b (backspace) character in CSS.
Published Dec 13, 2013 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.
Published Dec 7, 2013 · Updated Aug 6, 2024