Search Results (82411 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-7381 1 Libnotify Project 1 Libnotify 2024-11-21 9.8 Critical
libnotify before 1.0.4 for Node.js allows remote attackers to execute arbitrary commands via unspecified characters in a call to libnotify.notify.
CVE-2013-7380 1 Ep Imageconvert Project 1 Ep Imageconvert 2024-11-21 9.8 Critical
The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability
CVE-2013-7378 1 Hubot Scripts Project 1 Hubot Scripts 2024-11-21 9.8 Critical
scripts/email.coffee in the Hubot Scripts module before 2.4.4 for Node.js allows remote attackers to execute arbitrary commands.
CVE-2013-7371 2 Debian, Sencha 2 Debian Linux, Connect 2024-11-21 6.1 Medium
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)
CVE-2013-7370 4 Debian, Opensuse, Redhat and 1 more 4 Debian Linux, Opensuse, Openshift and 1 more 2024-11-21 6.1 Medium
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
CVE-2013-7351 1 Shaarli Project 1 Shaarli 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDailyRSS function; a (4) file name to the importFile function; or (5) vectors related to bookmarks.
CVE-2013-7324 1 Webkitgtk 1 Webkitgtk 2024-11-21 5.3 Medium
Webkit-GTK 2.x (any version with HTML5 audio/video support based on GStreamer) allows remote attackers to trigger unexpectedly high sound volume via malicious javascript. NOTE: this WebKit-GTK behavior complies with existing W3C standards and existing practices for GNOME desktop integration.
CVE-2013-7098 1 Infradead 1 Openconnect 2024-11-21 9.8 Critical
OpenConnect VPN client with GnuTLS before 5.02 contains a heap overflow if MTU is increased on reconnection.
CVE-2013-7071 1 Fibranet 1 Monitorix 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
CVE-2013-7070 1 Fibranet 1 Monitorix 2024-11-21 9.8 Critical
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.
CVE-2013-7062 1 Plone 1 Plone 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x through 4.2.7, and 4.3 through 4.3.2, allow remote attackers to inject arbitrary web script or HTML via unspecified input in the (1) browser_id_manager or (2) OFS.Image method.
CVE-2013-7054 1 Dlink 2 Dir-100, Dir-100 Firmware 2024-11-21 6.1 Medium
D-Link DIR-100 4.03B07: cli.cgi XSS
CVE-2013-6880 1 Elvedia 1 Flashcanvas 2024-11-21 6.1 Medium
Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header.
CVE-2013-6878 1 Miwisoft 1 Mijosearch 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remote attackers to inject arbitrary web script or HTML via the query parameter to component/mijosearch/search.
CVE-2013-6495 1 Redhat 3 Jboss Enterprise Application Platform, Jboss Enterprise Portal Platform, Jboss Portal 2024-11-21 6.1 Medium
JBossWeb Bayeux has reflected XSS
CVE-2013-6461 3 Debian, Nokogiri, Redhat 7 Debian Linux, Nokogiri, Cloudforms Management Engine and 4 more 2024-11-21 6.5 Medium
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
CVE-2013-6460 3 Debian, Nokogiri, Redhat 7 Debian Linux, Nokogiri, Cloudforms Management Engine and 4 more 2024-11-21 6.5 Medium
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
CVE-2013-6451 1 Mediawiki 1 Mediawiki 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecified CSS values.
CVE-2013-6430 2 Pivotal Software, Redhat 3 Spring Framework, Jboss Amq, Jboss Fuse 2024-11-21 5.4 Medium
The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket.
CVE-2013-6364 2 Debian, Horde 2 Debian Linux, Groupware 2024-11-21 8.8 High
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book