CVE-2013-6000 to CVE-2013-6999
101 CVEs with public proof-of-concept exploits.
- CVE-2013-60171 PoCCross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or…
- CVE-2013-60213 PoCsBuffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long…
- CVE-2013-60232 PoCsDirectory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read…
- CVE-2013-60251 PoCThe XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files…
- CVE-2013-60271 PoCStack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated…
- CVE-2013-60311 PoCThe Huawei E355 adapter with firmware 21.157.37.01.910 does not require authentication for API pages, which allows remote attackers to…
- CVE-2013-60405 PoCsMW6 Aztec, DataMatrix, and MaxiCode ActiveX controls versions before 4.0 are vulnerable to arbitrary code via crafted HTML document.
- CVE-2013-60411 PoCindex.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a…
- CVE-2013-60421 PoCCross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo before 2.1.4 allows…
- CVE-2013-60431 PoCThe login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on…
- CVE-2013-60582 PoCsSQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO…
- CVE-2013-60794 PoCsBuffer overflow in MostGear Soft Easy LAN Folder Share 3.2.0.100 allows local users to cause a denial of service (application crash) and…
- CVE-2013-61142 PoCsInteger overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denial of service…
- CVE-2013-61174 PoCsDahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user…
- CVE-2013-61272 PoCsThe SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly…
- CVE-2013-61282 PoCsThe KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly…
- CVE-2013-61293 PoCsThe install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid,…
- CVE-2013-61622 PoCsCross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script…
- CVE-2013-61642 PoCsSQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrary SQL commands via…
- CVE-2013-61661 PoCGoogle Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which…
- CVE-2013-61671 PoCMozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions,…
- CVE-2013-61943 PoCsUnspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service…
- CVE-2013-62213 PoCsDirectory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server…
- CVE-2013-62252 PoCsLiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
- CVE-2013-62271 PoCUnrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before…
- CVE-2013-62293 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbitrary web script…
- CVE-2013-62312 PoCsSpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
- CVE-2013-62322 PoCsCross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML…
- CVE-2013-62332 PoCsCross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML…
- CVE-2013-62342 PoCsUnrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute…
- CVE-2013-62362 PoCsIZON IP 2.0.2: hard-coded password vulnerability
- CVE-2013-62391 PoCCross-site scripting (XSS) vulnerability in the photo gallery model in Exis Contexis before 2.0 allows remote attackers to inject…
- CVE-2013-62461 PoCThe Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information…
- CVE-2013-62711 PoCAndroid 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that…
- CVE-2013-62722 PoCsThe NotificationBroadcastReceiver class in the com.android.phone process in Google Android 4.1.1 through 4.4.2 allows attackers to bypass…
- CVE-2013-62752 PoCsMultiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.
- CVE-2013-62811 PoCCross-site scripting (XSS) vulnerability in codebase/spreadsheet.php in the Spreadsheet (dhtmlxSpreadsheet) plugin 2.0 for WordPress…
- CVE-2013-62827 PoCsKEVThe (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain…
- CVE-2013-62832 PoCsVideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary…
- CVE-2013-62952 PoCsPrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module
- CVE-2013-63412 PoCsSQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language…
- CVE-2013-63433 PoCsMultiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers…
- CVE-2013-63571 PoCCross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to…
- CVE-2013-63581 PoCPrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in…
- CVE-2013-63642 PoCsHorde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
- CVE-2013-63662 PoCsThe Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a…
- CVE-2013-63751 PoCXen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table…
- CVE-2013-63951 PoCCross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web…
- CVE-2013-64141 PoCactionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote…
- CVE-2013-64201 PoCThe asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not…
- CVE-2013-64801 PoCLibcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain…
- CVE-2013-64901 PoCThe SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative…
- CVE-2013-64921 PoCThe Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass…
- CVE-2013-66182 PoCsjsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before…
- CVE-2013-66271 PoCnet/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status codes,…
- CVE-2013-66322 PoCsInteger overflow in Google Chrome before 31.0.1650.57 allows remote attackers to execute arbitrary code or cause a denial of service…
- CVE-2013-66742 PoCsCross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey…
- CVE-2013-67192 PoCsdelivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before…
- CVE-2013-67202 PoCsDirectory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through…
- CVE-2013-67351 PoCIBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x…
- CVE-2013-67651 PoCOpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute…
- CVE-2013-67672 PoCsStack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary code or cause a…
- CVE-2013-67851 PoCDirectory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read…
- CVE-2013-67872 PoCsSQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the…
- CVE-2013-67921 PoCGoogle Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
- CVE-2013-67932 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote attackers to inject…
- CVE-2013-67941 PoCCross-site scripting (XSS) vulnerability in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allows remote attackers to inject arbitrary…
- CVE-2013-67962 PoCsThe SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP…
- CVE-2013-67971 PoCCross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for…
- CVE-2013-67991 PoCApple Mac OS X 10.9 allows local users to cause a denial of service (memory corruption or panic) by creating a hard link to a directory.…
- CVE-2013-68091 PoCFormat string vulnerability in the client in Tftpd32 before 4.50 allows remote servers to cause a denial of service (crash) or possibly…
- CVE-2013-68102 PoCsThe server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN…
- CVE-2013-68261 PoCcgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token…
- CVE-2013-68292 PoCsadmin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-2013-68301 PoCadmin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute…
- CVE-2013-68311 PoCPineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user…
- CVE-2013-68351 PoCTelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which…
- CVE-2013-68391 PoCSQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and earlier allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2013-68522 PoCsCross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication…
- CVE-2013-68722 PoCsSQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL…
- CVE-2013-68731 PoCSQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arbitrary SQL…
- CVE-2013-68742 PoCsStack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a long URL in a .m3u…
- CVE-2013-68751 PoCSQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote…
- CVE-2013-68771 PoCHeap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote…
- CVE-2013-68801 PoCOpen redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct…
- CVE-2013-68812 PoCsCRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell…
- CVE-2013-68822 PoCsMultiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1)…
- CVE-2013-68832 PoCsCross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers…
- CVE-2013-68842 PoCsThe write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which…
- CVE-2013-68901 PoCdenyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of…
- CVE-2013-69222 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow…
- CVE-2013-69232 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote…
- CVE-2013-69243 PoCsSeagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell…
- CVE-2013-69341 PoCThe parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows…
- CVE-2013-69353 PoCsBuffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the…
- CVE-2013-69362 PoCsMultiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow…
- CVE-2013-69372 PoCsBuffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the…
- CVE-2013-69552 PoCswebman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1…
- CVE-2013-69764 PoCsCross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers to hijack the…
- CVE-2013-69851 PoCSQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows remote attackers…
- CVE-2013-69873 PoCsMultiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3…