CVE-2013-4000 to CVE-2013-4999
133 CVEs with public proof-of-concept exploits.
- CVE-2013-40021 PoCXMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0…
- CVE-2013-40113 PoCsMultiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users…
- CVE-2013-40151 PoCMicrosoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced…
- CVE-2013-40341 PoCIBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and…
- CVE-2013-40743 PoCsThe dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x…
- CVE-2013-40911 PoCThe SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute…
- CVE-2013-40921 PoCThe SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain…
- CVE-2013-40931 PoCThe SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive…
- CVE-2013-40941 PoCThe Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote…
- CVE-2013-40951 PoCplain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote…
- CVE-2013-40961 PoCServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via…
- CVE-2013-40971 PoCServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct…
- CVE-2013-40981 PoCServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message…
- CVE-2013-41031 PoCCryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
- CVE-2013-41173 PoCsCross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows…
- CVE-2013-41231 PoCclient_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a…
- CVE-2013-41242 PoCsInteger overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before…
- CVE-2013-41471 PoCMultiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a…
- CVE-2013-41641 PoCHeap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision…
- CVE-2013-42001 PoCThe isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1…
- CVE-2013-42114 PoCsA Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a…
- CVE-2013-42123 PoCsCertain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL…
- CVE-2013-42401 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote…
- CVE-2013-42413 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to…
- CVE-2013-42741 PoCCross-site scripting (XSS) vulnerability in the password_policy_admin_view function in password_policy.admin.inc in the Password Policy…
- CVE-2013-42751 PoCCross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3.x before 7.x-3.2,…
- CVE-2013-42951 PoCThe gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing…
- CVE-2013-43051 PoCCross-site scripting (XSS) vulnerability in contrib/example.php in the SyntaxHighlight GeSHi extension for MediaWiki, possibly as…
- CVE-2013-43181 PoCFile injection vulnerability in Ruby gem Features 0.3.0 allows remote attackers to inject malicious html in the /tmp directory.
- CVE-2013-43221 PoCApache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1)…
- CVE-2013-43381 PoCwp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote…
- CVE-2013-43391 PoCWordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended…
- CVE-2013-43401 PoCwp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the…
- CVE-2013-43413 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before…
- CVE-2013-43481 PoCThe skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of…
- CVE-2013-43622 PoCsWEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1)…
- CVE-2013-43781 PoCCross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to…
- CVE-2013-44341 PoCDropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the…
- CVE-2013-44501 PoCThe HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and…
- CVE-2013-44673 PoCsMultiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1,…
- CVE-2013-44683 PoCsVICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary…
- CVE-2013-44741 PoCFormat string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause…
- CVE-2013-44902 PoCsThe SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3,…
- CVE-2013-45473 PoCsnginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character…
- CVE-2013-45571 PoCThe Security Screen (_core_/securite/ecran_securite.php) before 1.1.8 for SPIP, as used in SPIP 3.0.x before 3.0.12, allows remote…
- CVE-2013-45791 PoCThe ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID…
- CVE-2013-46141 PoCEnglish/pages_MacUS/wls_set_content.html on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers shows…
- CVE-2013-46151 PoCThe Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of…
- CVE-2013-46201 PoCCross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote attackers to…
- CVE-2013-46242 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web…
- CVE-2013-46252 PoCsCross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote…
- CVE-2013-46302 PoCsStack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers…
- CVE-2013-46311 PoCHuawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 is enabled, allow remote attackers to cause a denial of service (device…
- CVE-2013-46592 PoCsBuffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is…
- CVE-2013-46604 PoCsThe JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote…
- CVE-2013-46642 PoCsSPBAS Business Automation Software 2012 has XSS.
- CVE-2013-46652 PoCsSPBAS Business Automation Software 2012 has CSRF.
- CVE-2013-46791 PoCSymantec Workspace Virtualization before 6.x before 6.4.1953.0, when a virtual application layer is configured, allows local users to gain…
- CVE-2013-46923 PoCsXorbin Analog Flash Clock 1.0 extension for Joomia has XSS
- CVE-2013-46931 PoCWordPress Xorbin Digital Flash Clock 1.0 has XSS
- CVE-2013-46943 PoCsStack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service…
- CVE-2013-46952 PoCsWinamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution
- CVE-2013-47104 PoCsAndroid 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView…
- CVE-2013-47271 PoCDDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain…
- CVE-2013-473010 PoCsBuffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command.
- CVE-2013-47432 PoCsStatic HTTP Server 1.0 has a Local Overflow
- CVE-2013-47591 PoCMultiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS…
- CVE-2013-47751 PoCNETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6;…
- CVE-2013-47761 PoCNETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier, GS748Tv4 5.4.1.14, and GS510TP 5.0.4.4 allows remote attackers…
- CVE-2013-47771 PoCA certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit…
- CVE-2013-47821 PoCThe Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher…
- CVE-2013-47864 PoCsThe IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to…
- CVE-2013-47871 PoCAndroid 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to…
- CVE-2013-47883 PoCsThe PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not…
- CVE-2013-47891 PoCSQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2013-47911 PoCPrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
- CVE-2013-47921 PoCPrestaShop before 1.4.11 allows logout CSRF.
- CVE-2013-47982 PoCsUnspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka…
- CVE-2013-48002 PoCsUnspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka…
- CVE-2013-48101 PoCKEVHP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow…
- CVE-2013-48112 PoCsUpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity…
- CVE-2013-48122 PoCsUpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity…
- CVE-2013-48222 PoCsUnspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka…
- CVE-2013-48231 PoCUnspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka…
- CVE-2013-48241 PoCUnspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote…
- CVE-2013-48261 PoCUnspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote…
- CVE-2013-48353 PoCsThe APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute…
- CVE-2013-48372 PoCsUnspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via…
- CVE-2013-48581 PoCMicrosoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a…
- CVE-2013-48592 PoCsINSTEON Hub 2242-222 lacks Web and API authentication
- CVE-2013-48613 PoCsDirectory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated…
- CVE-2013-48623 PoCsMiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the…
- CVE-2013-48635 PoCsThe HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code…
- CVE-2013-48643 PoCsMiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to…
- CVE-2013-48653 PoCsCross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers…
- CVE-2013-48672 PoCsElectronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking
- CVE-2013-48682 PoCsKarotz API 12.07.19.00: Session Token Information Disclosure
- CVE-2013-48782 PoCsThe default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper…
- CVE-2013-48791 PoCSQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary…
- CVE-2013-48801 PoCCross-site scripting (XSS) vulnerability in core/admin/modules/developer/modules/views/add.php in BigTree CMS 4.0 RC2 and earlier allows…
- CVE-2013-48811 PoCCross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote…
- CVE-2013-48821 PoCMultiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for…
- CVE-2013-48831 PoCMultiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee…
- CVE-2013-48842 PoCsCross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script or HTML via UTF-7…
- CVE-2013-48851 PoCThe http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload…
- CVE-2013-48871 PoCSQL injection vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2013-48882 PoCsCross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script…
- CVE-2013-48892 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attackers to hijack the…
- CVE-2013-48902 PoCsThe DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon crash) via a long URI…
- CVE-2013-48911 PoCThe xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct…
- CVE-2013-48982 PoCsUnrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote…
- CVE-2013-49003 PoCsDirectory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read…
- CVE-2013-49452 PoCsMultiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL…
- CVE-2013-49462 PoCsMultiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary…
- CVE-2013-49482 PoCsSQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter.
- CVE-2013-49492 PoCsUnrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP…
- CVE-2013-49502 PoCsCross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2013-49511 PoCMultiple cross-site scripting (XSS) vulnerabilities in Mintboard 0.3 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2013-49522 PoCsSQL injection vulnerability in functions/global.php in Elemata CMS RC 3.0 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2013-49532 PoCsSQL injection vulnerability in play.php in Top Games Script 1.2 allows remote attackers to execute arbitrary SQL commands via the gid…
- CVE-2013-49541 PoCMultiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for…
- CVE-2013-49752 PoCsHikvision DS-2CD7153-E IP Camera has Privilege Escalation
- CVE-2013-49762 PoCsHikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials
- CVE-2013-49771 PoCBuffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other…
- CVE-2013-49781 PoCStack-based buffer overflow in AloahaPDFViewer 5.0.0.7 and earlier in Aloaha PDF Suite FREE allows remote attackers to execute arbitrary…
- CVE-2013-49801 PoCBuffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices,…
- CVE-2013-49811 PoCBuffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices,…
- CVE-2013-49823 PoCsAVTECH AVN801 DVR has a security bypass via the administration login captcha
- CVE-2013-49833 PoCsThe get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers…
- CVE-2013-49844 PoCsThe close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local…
- CVE-2013-49853 PoCsMultiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream
- CVE-2013-49871 PoCPineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell…
- CVE-2013-49885 PoCsStack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCount value in an…