Search Results (82397 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-4267 1 Pydio 1 Pydio 2024-11-21 9.8 Critical
Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSController.php), a (2) file name to the getTrustSizeOnFileSystem function in the File System (Standard) module (plugins/access.fs/class.fsAccessWrapper.php), or the (3) revision parameter to the Subversion Repository module (plugins/meta.svn/class.SvnManager.php).
CVE-2013-4241 1 Hitmyserver 1 Hms Testimonials 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-testimonials-addnew page); (5) date_format parameter to the Settings - Default form (hms-testimonials-settings page); (6) name parameter in a Save action to the Settings - Custom Fields form (hms-testimonials-settings-fields page); or (7) name parameter in a Save action to the Settings - Template form (hms-testimonials-templates-new page).
CVE-2013-4225 2 Redhat, Restful Web Services Project 2 Satellite, Restful Web Services 2024-11-21 8.8 High
The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users with the "access resource node" and "create page content" permissions (or equivalents) to conduct cross-site scripting (XSS) or execute arbitrary PHP code via a crafted text field.
CVE-2013-4170 1 Emberjs 1 Ember.js 2024-11-21 6.1 Medium
In general, Ember.js escapes or strips any user-supplied content before inserting it in strings that will be sent to innerHTML. However, the `tagName` property of an `Ember.View` was inserted into such a string without being sanitized. This means that if an application assigns a view's `tagName` to user-supplied data, a specially-crafted payload could execute arbitrary JavaScript in the context of the current domain ("XSS"). This vulnerability only affects applications that assign or bind user-provided content to `tagName`.
CVE-2013-4168 3 Debian, Fedoraproject, Smokeping 3 Debian Linux, Fedora, Smokeping 2024-11-21 6.1 Medium
Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
CVE-2013-4158 3 Debian, Fedoraproject, Smokeping 3 Debian Linux, Fedora, Smokeping 2024-11-21 6.1 Medium
smokeping before 2.6.9 has XSS (incomplete fix for CVE-2012-0790)
CVE-2013-4144 1 Swfupload Project 1 Swfupload 2024-11-21 9.8 Critical
There is an object injection vulnerability in swfupload plugin for wordpress.
CVE-2013-4109 1 Cryptocat Project 1 Cryptocat 2024-11-21 6.1 Medium
An unspecified cross-site scripting (XSS) vulnerability exists in Cryptocat Message Handling 1.1.165.
CVE-2013-4107 1 Cryptocat Project 1 Cryptocat 2024-11-21 6.1 Medium
Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting
CVE-2013-4106 1 Cryptocat Project 1 Cryptocat 2024-11-21 6.1 Medium
A Cross-site scripting (XSS) vulnerability exists in Conversation Overview Nickname in Cryptocat before 2.0.22.
CVE-2013-3946 1 Extensis 1 Mrsid 2024-11-21 7.8 High
Heap-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a levels header.
CVE-2013-3944 1 Extensis 1 Mrsid 2024-11-21 7.8 High
Stack-based buffer overflow in the MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via an IMAGE tag.
CVE-2013-3941 1 Xnview 1 Xnview 2024-11-21 9.8 Critical
Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a QCD marker in a crafted JPEG2000 file, which leads to a heap-based buffer overflow.
CVE-2013-3939 1 Xnview 1 Xnview 2024-11-21 7.8 High
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a RGB file, which leads to an unexpected sign extension error and a heap-based buffer overflow.
CVE-2013-3937 1 Xnview 1 Xnview 2024-11-21 7.8 High
Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file.
CVE-2013-3936 1 Opsview 2 Opsview, Opsview Core 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 and Opsview Core before 20130522 allow remote attackers to inject arbitrary web script or HTML.
CVE-2013-3931 1 Jomres 1 Jomres 2024-11-21 5.4 Medium
Cross-site scripting (XSS) vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users with the "Business Manager" permission to inject arbitrary web script or HTML via the property_name parameter, related to editing property details.
CVE-2013-3637 1 Projectpier 1 Projectpier 2024-11-21 5.4 Medium
ProjectPier 0.8.8 does not use the Secure flag for cookies
CVE-2013-3636 1 Projectpier 1 Projectpier 2024-11-21 5.4 Medium
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
CVE-2013-3635 1 Projectpier 1 Projectpier 2024-11-21 5.4 Medium
ProjectPier 0.8.8 has stored XSS