Search Results (7481 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2014-125069 1 Maps-js-icoads Project 1 Maps-js-icoads 2024-11-21 4.3 Medium
A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217644.
CVE-2014-0243 1 Check Mk Project 1 Check Mk 2024-11-21 N/A
Check_MK through 1.2.5i2p1 allows local users to read arbitrary files via a symlink attack to a file in /var/lib/check_mk_agent/job.
CVE-2014-0241 2 Redhat, Theforeman 2 Satellite, Hammer Cli 2024-11-21 5.5 Medium
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
CVE-2013-7489 1 Beakerbrowser 1 Beaker 2024-11-21 6.8 Medium
The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.
CVE-2013-7055 1 Dlink 2 Dir-100, Dir-100 Firmware 2024-11-21 9.8 Critical
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
CVE-2013-7052 1 Dlink 2 Dir-100, Dir-100 Firmware 2024-11-21 9.8 Critical
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
CVE-2013-5113 1 Logmein 1 Lastpass 2024-11-21 6.8 Medium
LastPass prior to 2.5.1 has an insecure PIN implementation.
CVE-2013-4655 1 Belkin 2 N900, N900 Firmware 2024-11-21 7.5 High
Symlink Traversal vulnerability in Belkin N900 due to misconfiguration in the SMB service.
CVE-2013-4521 1 Nuxeo 1 Nuxeo 2024-11-21 9.8 Critical
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: this vulnerability may overlap CVE-2013-2165.
CVE-2013-4423 1 Redhat 2 Cloudforms, Cloudforms Managementengine 2024-11-21 5.5 Medium
CloudForms stores user passwords in recoverable format
CVE-2013-4364 1 Redhat 1 Openshift 2024-11-21 N/A
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.
CVE-2013-4251 4 Debian, Fedoraproject, Redhat and 1 more 4 Debian Linux, Fedora, Enterprise Linux and 1 more 2024-11-21 7.8 High
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
CVE-2013-4184 2 Data\, Debian 2 \, Debian Linux 2024-11-21 5.5 Medium
Perl module Data::UUID from CPAN version 1.219 vulnerable to symlink attacks
CVE-2013-3620 2 Citrix, Supermicro 10 Netscaler, Netscaler Firmware, Netscaler Sd-wan and 7 more 2024-11-21 7.5 High
Hardcoded WSMan credentials in Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before 3.15 (SMT_X9_315) and firmware for Supermicro X8 generation motherboards before SMT X8 312.
CVE-2013-3313 1 Loftek 2 Nexus 543, Nexus 543 Firmware 2024-11-21 7.5 High
The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive information via an HTTP GET request to check_users.cgi. NOTE: cleartext passwords can also be obtained from proc/kcore when leveraging the directory traversal vulnerability in CVE-2013-3311.
CVE-2013-2672 1 Brother 2 Mfc-9970cdw, Mfc-9970cdw Firmware 2024-11-21 7.5 High
Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
CVE-2013-2106 2 Debian, Stanford 2 Debian Linux, Webauth 2024-11-21 7.5 High
webauth before 4.6.1 has authentication credential disclosure
CVE-2013-1867 1 Apple 2 Mac Os X, Tokend 2024-11-21 6.1 Medium
Gemalto Tokend 2013 has an Arbitrary File Creation/Overwrite Vulnerability
CVE-2013-1866 2 Apple, Opensc Project 2 Mac Os X, Opensc 2024-11-21 6.1 Medium
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
CVE-2013-1809 2 Debian, Gambas Project 2 Debian Linux, Gambas 2024-11-21 7.5 High
Gambas before 3.4.0 allows remote attackers to move or manipulate directory contents or perform symlink attacks due to the creation of insecure temporary directories.