Total
9170 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-6482 | 1 Pidgin | 1 Pidgin | 2014-03-15 | 5.0 MEDIUM | N/A |
Pidgin before 2.10.8 allows remote MSN servers to cause a denial of service (NULL pointer dereference and crash) via a crafted (1) SOAP response, (2) OIM XML response, or (3) Content-Length header. | |||||
CVE-2013-6483 | 1 Pidgin | 1 Pidgin | 2014-03-15 | 6.4 MEDIUM | N/A |
The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remote attackers to spoof iq traffic or cause a denial of service (NULL pointer dereference and application crash) via a crafted reply. | |||||
CVE-2013-6484 | 1 Pidgin | 1 Pidgin | 2014-03-15 | 5.0 MEDIUM | N/A |
The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write operation and application crash) by triggering a socket read error. | |||||
CVE-2013-3948 | 1 Apple | 1 Iphone Os | 2014-03-15 | 4.3 MEDIUM | N/A |
Apple iOS 6.1.3 does not follow redirects during determination of the hostname to display in an iOS Enterprise Deployment installation dialog, which makes it easier for remote attackers to trigger installation of arbitrary applications via a download-manifest itms-services:// URL that leverages an open redirect vulnerability within a trusted domain. | |||||
CVE-2012-6152 | 1 Pidgin | 1 Pidgin | 2014-03-15 | 5.0 MEDIUM | N/A |
The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denial of service (application crash) via crafted byte sequences. | |||||
CVE-2013-7335 | 1 Dotnetnuke | 1 Dotnetnuke | 2014-03-13 | 4.3 MEDIUM | N/A |
Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |||||
CVE-2013-4199 | 1 Plone | 1 Plone | 2014-03-11 | 3.5 LOW | N/A |
(1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompressed). | |||||
CVE-2013-4197 | 1 Plone | 1 Plone | 2014-03-11 | 5.5 MEDIUM | N/A |
member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors. | |||||
CVE-2013-4195 | 1 Plone | 1 Plone | 2014-03-11 | 5.8 MEDIUM | N/A |
Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |||||
CVE-2013-4192 | 1 Plone | 1 Plone | 2014-03-11 | 4.0 MEDIUM | N/A |
sendto.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to spoof emails via unspecified vectors. | |||||
CVE-2011-1749 | 1 Linux-nfs | 1 Nfs-utils | 2014-03-10 | 3.3 LOW | N/A |
The nfs_addmntent function in support/nfs/nfs_mntent.c in the mount.nsf tool in nfs-utils before 1.2.4 attempts to append to the /etc/mtab file without first checking whether resource limits would interfere, which allows local users to corrupt this file via a process with a small RLIMIT_FSIZE value, a related issue to CVE-2011-1089. | |||||
CVE-2011-2941 | 1 Redhat | 1 Jboss Enterprise Portal Platform | 2014-03-10 | 5.8 MEDIUM | N/A |
Open redirect vulnerability in Red Hat JBoss Enterprise Portal Platform before 5.2.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the initialURI parameter. | |||||
CVE-2013-4710 | 1 Google | 1 Android | 2014-03-10 | 9.3 HIGH | N/A |
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636. | |||||
CVE-2013-0846 | 1 Ffmpeg | 1 Ffmpeg | 2014-03-07 | 9.3 HIGH | N/A |
Array index error in the qdm2_decode_super_block function in libavcodec/qdm2.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted QDM2 data, which triggers an out-of-bounds array access. | |||||
CVE-2013-0849 | 1 Ffmpeg | 1 Ffmpeg | 2014-03-07 | 9.3 HIGH | N/A |
The roq_decode_init function in libavcodec/roqvideodec.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a crafted (1) width or (2) height dimension that is not a multiple of sixteen in id RoQ video data. | |||||
CVE-2013-3242 | 1 Joomla | 1 Joomla\! | 2014-03-07 | 5.5 MEDIUM | N/A |
plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated users to conduct PHP object injection attacks and cause a denial of service via unspecified vectors. | |||||
CVE-2013-6048 | 1 Munin-monitoring | 1 Munin | 2014-03-05 | 5.0 MEDIUM | N/A |
The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data. | |||||
CVE-2013-6359 | 1 Munin-monitoring | 1 Munin | 2014-03-05 | 4.3 MEDIUM | N/A |
Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name. | |||||
CVE-2013-6636 | 1 Google | 1 Chrome | 2014-03-05 | 4.3 MEDIUM | N/A |
The FrameLoader::notifyIfInitialDocumentAccessed function in core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 31.0.1650.63, makes an incorrect check for an empty document during presentation of a modal dialog, which allows remote attackers to spoof the address bar via vectors involving the document.write method. | |||||
CVE-2014-2234 | 1 Apple | 1 Mac Os X | 2014-03-05 | 6.4 MEDIUM | N/A |
A certain Apple patch for OpenSSL in Apple OS X 10.9.2 and earlier uses a Trust Evaluation Agent (TEA) feature without terminating certain TLS/SSL handshakes as specified in the SSL_CTX_set_verify callback function's documentation, which allows remote attackers to bypass extra verification within a custom application via a crafted certificate chain that is acceptable to TEA but not acceptable to that application. |