Search Results (76102 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-7172 1 Slackware 1 Slackware Linux 2024-08-06 7.8 High
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.
CVE-2024-7502 1 Deltaww 1 Diascreen 2024-08-06 7.8 High
A crafted DPA file could force Delta Electronics DIAScreen to overflow a stack-based buffer, which could allow an attacker to execute arbitrary code.
CVE-2013-7051 1 Dlink 2 Dir-100, Dir-100 Firmware 2024-08-06 8.8 High
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
CVE-2013-7053 1 Dlink 2 Dir-100, Dir-100 Firmware 2024-08-06 8.8 High
D-Link DIR-100 4.03B07: cli.cgi CSRF
CVE-2024-7439 1 Vivotek 2 Cc8160, Cc8160 Firmware 2024-08-06 8.8 High
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek CC8160 VVTK-0100d and classified as critical. Affected by this issue is the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273524. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.
CVE-2013-6773 2 Microsoft, Splunk 2 Windows, Splunk 2024-08-06 7.8 High
Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges
CVE-2013-6811 1 D-link 2 Dsl6740u, Dsl6740u Firmware 2024-08-06 8.8 High
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change administrator credentials or enable remote management services to (1) Custom Services in Port Forwarding, (2) Port Triggering Entries, (3) URL Filters in Parental Control, (4) Print Server settings, (5) QoS Queue Setup, or (6) QoS Classification Entries.
CVE-2013-6648 1 Google 1 Skia 2024-08-06 7.5 High
SkRegion::setPath in Skia allows remote attackers to cause a denial of service (crash).
CVE-2024-7441 1 Vivotek 2 Sd9364, Sd9364 Firmware 2024-08-06 8.8 High
** UNSUPPORTED WHEN ASSIGNED ** A vulnerability was found in Vivotek SD9364 VVTK-0103f. It has been declared as critical. This vulnerability affects the function read of the component httpd. The manipulation of the argument Content-Length leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-273526 is the identifier assigned to this vulnerability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the affected release tree is end-of-life.
CVE-2013-6360 1 Trendnet 2 Ts-s402, Ts-s402 Firmware 2024-08-06 7.5 High
TRENDnet TS-S402 has a backdoor to enable TELNET.
CVE-2013-6358 1 Prestashop 1 Prestashop 2024-08-06 8.8 High
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
CVE-2013-6277 1 Qnap 2 Viocard 300, Viocard 300 Firmware 2024-08-06 7.5 High
QNAP VioCard 300 has hardcoded RSA private keys.
CVE-2013-6231 1 Eng 1 Spagobi 2024-08-06 8.8 High
SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script
CVE-2013-6056 1 Alienvault 1 Open Source Security Information Management 2024-08-06 7.5 High
OSSIM before 4.3.3.1 has tele_compress.php path traversal vulnerability
CVE-2023-33322 2024-08-06 7.1 High
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Etoile Web Design Front End Users allows Reflected XSS.This issue affects Front End Users: from n/a before 3.2.25.
CVE-2013-5687 1 Aicorporation 1 Risknet Acquirer 2024-08-06 7.5 High
RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
CVE-2013-5657 1 Aultware 1 Pwstore 2024-08-06 7.5 High
AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request
CVE-2013-5656 1 Fuzezip Project 1 Fuzezip 2024-08-06 7.8 High
FuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerability
CVE-2013-5659 1 Info-zip 1 Wiz 2024-08-06 7.5 High
Wiz 5.0.3 has a user mode write access violation
CVE-2013-5582 1 Ammyy 1 Ammyy Admin 2024-08-06 7.8 High
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.