Total
210374 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2012-5454 | 1 Atutor | 1 Acontent | 2013-04-10 | 6.5 MEDIUM | N/A |
| user/index_inline_editor_submit.php in ATutor AContent 1.2-1 does not properly restrict access, which allows remote authenticated users to modify arbitrary user passwords via a crafted request. NOTE: this might be due to an incomplete fix for CVE-2012-5168. | |||||
| CVE-2012-4002 | 1 Glpi-project | 1 Glpi | 2013-04-10 | 6.8 MEDIUM | N/A |
| Cross-site request forgery (CSRF) vulnerability in GLPI-PROJECT GLPI before 0.83.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |||||
| CVE-2012-4003 | 1 Glpi-project | 1 Glpi | 2013-04-10 | 4.3 MEDIUM | N/A |
| Multiple cross-site scripting (XSS) vulnerabilities in GLPI-PROJECT GLPI before 0.83.3 allow remote attackers to inject arbitrary web script or HTML via unknown vectors. | |||||
| CVE-2012-3442 | 1 Djangoproject | 1 Django | 2013-04-10 | 4.3 MEDIUM | N/A |
| The (1) django.http.HttpResponseRedirect and (2) django.http.HttpResponsePermanentRedirect classes in Django before 1.3.2 and 1.4.x before 1.4.1 do not validate the scheme of a redirect target, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via a data: URL. | |||||
| CVE-2012-3443 | 1 Djangoproject | 1 Django | 2013-04-10 | 5.0 MEDIUM | N/A |
| The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a denial of service (memory consumption) by uploading an image file. | |||||
| CVE-2012-3444 | 1 Djangoproject | 1 Django | 2013-04-10 | 5.0 MEDIUM | N/A |
| The get_image_dimensions function in the image-handling functionality in Django before 1.3.2 and 1.4.x before 1.4.1 uses a constant chunk size in all attempts to determine dimensions, which allows remote attackers to cause a denial of service (process or thread consumption) via a large TIFF image. | |||||
| CVE-2012-6097 | 1 Fedorahosted | 1 Cronie | 2013-04-10 | 4.3 MEDIUM | N/A |
| File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab. | |||||
| CVE-2013-0284 | 1 Newrelic | 1 Ruby Agent | 2013-04-09 | 5.0 MEDIUM | N/A |
| Ruby agent 3.2.0 through 3.5.2 serializes sensitive data when communicating with servers operated by New Relic, which allows remote attackers to obtain sensitive information (database credentials and SQL statements) by sniffing the network and deserializing the data. | |||||
| CVE-2013-1383 | 1 Adobe | 1 Shockwave Player | 2013-04-09 | 10.0 HIGH | N/A |
| Buffer overflow in Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code via unspecified vectors. | |||||
| CVE-2013-1384 | 1 Adobe | 1 Shockwave Player | 2013-04-09 | 10.0 HIGH | N/A |
| Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-1386. | |||||
| CVE-2013-1385 | 1 Adobe | 1 Shockwave Player | 2013-04-09 | 10.0 HIGH | N/A |
| Adobe Shockwave Player before 12.0.2.122 does not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors. | |||||
| CVE-2013-1386 | 1 Adobe | 1 Shockwave Player | 2013-04-09 | 10.0 HIGH | N/A |
| Adobe Shockwave Player before 12.0.2.122 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-1384. | |||||
| CVE-2013-1789 | 1 Freedesktop | 1 Poppler | 2013-04-09 | 4.3 MEDIUM | N/A |
| splash/Splash.cc in poppler before 0.22.1 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to the (1) Splash::arbitraryTransformMask, (2) Splash::blitMask, and (3) Splash::scaleMaskYuXu functions. | |||||
| CVE-2013-1800 | 1 John Nunemaker | 1 Crack | 2013-04-09 | 7.5 HIGH | N/A |
| The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. | |||||
| CVE-2013-1801 | 1 John Nunemaker | 1 Httparty | 2013-04-09 | 7.5 HIGH | N/A |
| The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for YAML type conversion, a similar vulnerability to CVE-2013-0156. | |||||
| CVE-2013-1802 | 1 Dan Kubb | 1 Extlib | 2013-04-09 | 7.5 HIGH | N/A |
| The extlib gem 0.9.15 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156. | |||||
| CVE-2013-1898 | 1 Digineo | 1 Thumbshooter | 2013-04-09 | 7.5 HIGH | N/A |
| lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |||||
| CVE-2013-2778 | 1 Chatelao | 1 Php Address Book | 2013-04-09 | 7.5 HIGH | N/A |
| Cross-site request forgery (CSRF) vulnerability in addressbook/register/delete_user.php in PHP Address Book 8.2.5 allows remote attackers to hijack the authentication of administrators for requests that delete accounts, a different vulnerability than CVE-2013-0135.1. | |||||
| CVE-2013-0134 | 1 Airdroid | 1 Airdroid | 2013-04-09 | 4.3 MEDIUM | N/A |
| Cross-site scripting (XSS) vulnerability in the web interface in AirDroid allows remote attackers to inject arbitrary web script or HTML via a crafted text message that is transmitted by a managed phone. | |||||
| CVE-2013-0111 | 1 Nvidia | 1 Driver | 2013-04-09 | 6.8 MEDIUM | N/A |
| daemonu.exe (aka the NVIDIA Update Service Daemon), as distributed with the NVIDIA driver before 307.78, and Release 310 before 311.00, on Windows, lacks " (double quote) characters in the service path, which allows local users to gain privileges via a Trojan horse program. | |||||
