CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2013-4570

    Last Modified: 12 Apr 2025

    The zend_inline_hash_func function in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to converting Lua data structures to PHP, as demonstrated by passing { [{}] = 1 } to a module function.

    Published: 12 May 2014
    7.5
    High

    CVE-2013-4571

    Last Modified: 12 Apr 2025

    Buffer overflow in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 has unspecified impact and remote vectors.

    Published: 12 May 2014
    4.3
    Medium

    CVE-2013-4574

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the TimeMediaHandler extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to videos.

    Published: 12 May 2014
    2.1
    Low

    CVE-2013-4577

    Last Modified: 12 Apr 2025

    A certain Debian patch for GNU GRUB uses world-readable permissions for grub.cfg, which allows local users to obtain password hashes, as demonstrated by reading the password_pbkdf2 directive in the file.

    Published: 12 May 2014
    6.8
    Medium

    CVE-2013-4580

    Last Modified: 12 Apr 2025

    GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.

    Published: 12 May 2014
    6.8
    Medium

    CVE-2013-4581

    Last Modified: 12 Apr 2025

    GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.

    Published: 12 May 2014
    5
    Medium

    CVE-2013-6472

    Last Modified: 12 Apr 2025

    MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain information about deleted page via the (1) log API, (2) enhanced RecentChanges, and (3) user watchlists.

    Published: 12 May 2014
    5
    Medium

    CVE-2014-2301

    Last Modified: 12 Apr 2025

    OrbiTeam BSCW before 5.0.8 allows remote attackers to obtain sensitive metadata via the inf operations (op=inf) to an object in pub/bscw.cgi/.

    Published: 12 May 2014
    7.5
    High

    CVE-2013-5671

    Last Modified: 12 Apr 2025

    lib/dragonfly/imagemagickutils.rb in the fog-dragonfly gem 0.8.2 for Ruby allows remote attackers to execute arbitrary commands via unspecified vectors.

    Published: 12 May 2014
    6.8
    Medium

    CVE-2013-5748

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to hijack the authentication of users for requests that add projects via an add_project action.

    Published: 12 May 2014
    4.3
    Medium

    CVE-2013-5749

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to inject arbitrary web script or HTML via the new_project parameter.

    Published: 12 May 2014
    6.4
    Medium

    CVE-2013-5984

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in userfiles/modules/admin/backup/delete.php in Microweber before 0.830 allows remote attackers to delete arbitrary files via a .. (dot dot) in the file parameter.

    Published: 12 May 2014
    4.3
    Medium

    CVE-2013-6452

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via crafted XSL in an SVG file.

    Published: 12 May 2014
    7.5
    High

    CVE-2013-6453

    Last Modified: 12 Apr 2025

    MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 does not properly sanitize SVG files, which allows remote attackers to have unspecified impact via invalid XML.

    Published: 12 May 2014
    4.3
    Medium

    CVE-2013-6454

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via a -o-link attribute.

    Published: 12 May 2014
    9.3
    Critical

    CVE-2013-4772

    Last Modified: 12 Apr 2025

    D-Link DIR-505L SharePort Mobile Companion 1.01 and DIR-826L Wireless N600 Cloud Router 1.02 allows remote attackers to bypass authentication via a direct request when an authorized session is active.

    Published: 12 May 2014
    7.1
    High

    CVE-2014-2928

    Last Modified: 12 Apr 2025

    The iControl API in F5 BIG-IP LTM, APM, ASM, GTM, Link Controller, and PSM 10.0.0 through 10.2.4 and 11.0.0 through 11.5.1, BIG-IP AAM 11.4.0 through 11.5.1, BIG-IP AFM and PEM 11.3.0 through 11.5.1, BIG-IP Analytics 11.0.0 through 11.5.1, BIG-IP Edge Gateway, WebAccelerator, WOM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, Enterprise Manager 2.1.0 through 2.3.0 and 3.0.0 through 3.1.1, and BIG-IQ Cloud, Device, and Security 4.0.0 through 4.3.0 allows remote administrators to execute arbitrary commands via shell metacharacters in the hostname element in a SOAP request.

    Published: 12 May 2014
    6.8
    Medium

    CVE-2014-3454

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Special:CreateCategory in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to hijack the authentication of users for requests that create categories via unspecified vectors.

    Published: 12 May 2014
    6.8
    Medium

    CVE-2014-3455

    Last Modified: 12 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the (1) CreateProperty, (2) CreateTemplate, (3) CreateForm, and (4) CreateClass special pages in the SemanticForms extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allow remote attackers to hijack the authentication of users for requests that have unspecified impact and vectors.

    Published: 12 May 2014
    4
    Medium

    CVE-2014-0078

    Last Modified: 12 Apr 2025

    The CatalogController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to delete arbitrary catalogs via vectors involving guessing the catalog ID.

    Published: 12 May 2014
    4.6
    Medium

    CVE-2014-0223

    Last Modified: 12 Apr 2025

    Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a large image size, which triggers a buffer overflow or out-of-bounds read.

    Published: 12 May 2014
    5.8
    Medium

    CVE-2014-0878

    Last Modified: 12 Apr 2025

    The IBMSecureRandom component in the IBMJCE and IBMSecureRandom cryptographic providers in IBM SDK Java Technology Edition 5.0 before Service Refresh 16 FP6, 6 before Service Refresh 16, 6.0.1 before Service Refresh 8, 7 before Service Refresh 7, and 7R1 before Service Refresh 1 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the random number generator's output.

    Published: 12 May 2014
    6.5
    Medium

    CVE-2014-0137

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the saved_report_delete action in the ReportController in Red Hat CloudForms Management Engine (CFME) before 5.2.3.2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, related to MiqReportResult.exists.

    Published: 12 May 2014
    7.5
    High

    CVE-2014-0222

    Last Modified: 12 Apr 2025

    Integer overflow in the qcow_open function in block/qcow.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service (crash) via a large L2 table in a QCOW version 1 image.

    Published: 12 May 2014
    6.8
    Medium

    CVE-2014-3461

    Last Modified: 12 Apr 2025

    hw/usb/bus.c in QEMU 1.6.2 allows remote attackers to execute arbitrary code via crafted savevm data, which triggers a heap-based buffer overflow, related to "USB post load checks."

    Published: 12 May 2014
    1.7
    Low

    CVE-2014-2603

    Last Modified: 12 Apr 2025

    Unspecified vulnerability on HP 8/20q switches, SN6000 switches, and 8Gb Simple SAN Connection Kit with firmware before 8.0.14.08.00 allows remote authenticated users to obtain sensitive information via unknown vectors.

    Published: 10 May 2014
    4.3
    Medium

    CVE-2013-6220

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Network Node Manager i (NNMi) 9.0, 9.10, and 9.20 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 May 2014
    5.8
    Medium

    CVE-2014-1991

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in WebPlatform / AppFramework 6.0 through 7.2 in NTT DATA INTRAMART intra-mart allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 9 May 2014
    6
    Medium

    CVE-2014-0944

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote authenticated users to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 9 May 2014
    3.5
    Low

    CVE-2014-0945

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 9 May 2014
    4.3
    Medium

    CVE-2014-0946

    Last Modified: 12 Apr 2025

    The RES Console in Rule Execution Server in IBM Operational Decision Manager 7.5 before FP3 IF37, 8.0 before MP1 FP2, and 8.5 before MP1 IF26 does not send appropriate Cache-Control HTTP headers, which allows remote attackers to obtain sensitive information by leveraging an unattended workstation.

    Published: 9 May 2014
    4.3
    Medium

    CVE-2014-0913

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM iNotes and Domino 8.5.3 FP6 before IF2 and 9.0.1 before FP1 allows remote attackers to inject arbitrary web script or HTML via an e-mail message, aka SPR BFEY9GXHZE.

    Published: 9 May 2014
    5
    Medium

    CVE-2014-3430

    Last Modified: 12 Apr 2025

    Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.

    Published: 9 May 2014
    4.3
    Medium

    CVE-2014-2854

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the SemanticTitle extension before 1.1.0 for MediaWiki allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 May 2014
    4.3
    Medium

    CVE-2013-5916

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in falha.php in the Bradesco Gateway plugin 2.0 for Wordpress, as used in the WP e-Commerce plugin, allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING.

    Published: 8 May 2014
    4.9
    Medium

    CVE-2013-6889

    Last Modified: 12 Apr 2025

    GNU Rush 1.7 does not properly drop privileges, which allows local users to read arbitrary files via the --lint option.

    Published: 8 May 2014
    3.6
    Low

    CVE-2012-5477

    Last Modified: 12 Apr 2025

    The smart proxy in Foreman before 1.1 uses a umask set to 0, which allows local users to modify files created by the daemon via unspecified vectors.

    Published: 8 May 2014
    7.5
    High

    CVE-2013-0171

    Last Modified: 12 Apr 2025

    Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.

    Published: 8 May 2014
    5
    Medium

    CVE-2013-0174

    Last Modified: 12 Apr 2025

    The external node classifier (ENC) API in Foreman before 1.1 allows remote attackers to obtain the hashed root password via an API request.

    Published: 8 May 2014
    6.5
    Medium

    CVE-2013-0187

    Last Modified: 12 Apr 2025

    Foreman before 1.1 allows remote authenticated users to gain privileges via a (1) XMLHttpRequest or (2) AJAX request.

    Published: 8 May 2014
    7.5
    High

    CVE-2013-0210

    Last Modified: 12 Apr 2025

    The smart proxy Puppet run API in Foreman before 1.2.0 allows remote attackers to execute arbitrary commands via vectors related to escaping and Puppet commands.

    Published: 8 May 2014
    2.1
    Low

    CVE-2013-0345

    Last Modified: 12 Apr 2025

    varnish 3.0.3 uses world-readable permissions for the /var/log/varnish/ directory and the log files in the directory, which allows local users to obtain sensitive information by reading the files. NOTE: some of these details are obtained from third party information.

    Published: 8 May 2014
    2.6
    Low

    CVE-2013-3571

    Last Modified: 12 Apr 2025

    socat 1.2.0.0 before 1.7.2.2 and 2.0.0-b1 before 2.0.0-b6, when used for a listen type address and the fork option is enabled, allows remote attackers to cause a denial of service (file descriptor consumption) via multiple request that are refused based on the (1) sourceport, (2) lowport, (3) range, or (4) tcpwrap restrictions.

    Published: 8 May 2014
    4
    Medium

    CVE-2014-1682

    Last Modified: 12 Apr 2025

    The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.

    Published: 8 May 2014
    3.3
    Low

    CVE-2014-1934

    Last Modified: 12 Apr 2025

    tag.py in eyeD3 (aka python-eyed3) 7.0.3, 0.6.18, and earlier for Python allows local users to modify arbitrary files via a symlink attack on a temporary file.

    Published: 8 May 2014
    5
    Medium

    CVE-2013-0173

    Last Modified: 12 Apr 2025

    Foreman before 1.1 uses a salt of "foreman" to hash root passwords, which makes it easier for attackers to guess the password via a brute force attack.

    Published: 8 May 2014
    1.9
    Low

    CVE-2014-0135

    Last Modified: 12 Apr 2025

    Kafo before 0.3.17 and 0.4.x before 0.5.2, as used by Foreman, uses world-readable permissions for default_values.yaml, which allows local users to obtain passwords and other sensitive information by reading the file.

    Published: 8 May 2014
    5.5
    Medium

    CVE-2014-1685

    Last Modified: 12 Apr 2025

    The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.

    Published: 8 May 2014
    4.3
    Medium

    CVE-2014-2689

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in Offiria 2.1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to installer/index.php.

    Published: 8 May 2014
    4.3
    Medium

    CVE-2014-3207

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in wserver.ml in SKS Keyserver before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to pks/lookup/undefined1.

    Published: 8 May 2014