CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2012-6152

    Last Modified: 11 Apr 2025

    The Yahoo! protocol plugin in libpurple in Pidgin before 2.10.8 does not properly validate UTF-8 data, which allows remote attackers to cause a denial of service (application crash) via crafted byte sequences.

    Published: 28 Jan 2014
    5
    Medium

    CVE-2013-6477

    Last Modified: 11 Apr 2025

    Multiple integer signedness errors in libpurple in Pidgin before 2.10.8 allow remote attackers to cause a denial of service (application crash) via a crafted timestamp value in an XMPP message.

    Published: 28 Jan 2014
    5
    Medium

    CVE-2013-6481

    Last Modified: 11 Apr 2025

    libpurple/protocols/yahoo/libymsg.c in Pidgin before 2.10.8 allows remote attackers to cause a denial of service (crash) via a Yahoo! P2P message with a crafted length field, which triggers a buffer over-read.

    Published: 28 Jan 2014
    5
    Medium

    CVE-2013-6482

    Last Modified: 11 Apr 2025

    Pidgin before 2.10.8 allows remote MSN servers to cause a denial of service (NULL pointer dereference and crash) via a crafted (1) SOAP response, (2) OIM XML response, or (3) Content-Length header.

    Published: 28 Jan 2014
    5
    Medium

    CVE-2013-6484

    Last Modified: 11 Apr 2025

    The STUN protocol implementation in libpurple in Pidgin before 2.10.8 allows remote STUN servers to cause a denial of service (out-of-bounds write operation and application crash) by triggering a socket read error.

    Published: 28 Jan 2014
    5
    Medium

    CVE-2013-6485

    Last Modified: 11 Apr 2025

    Buffer overflow in util.c in libpurple in Pidgin before 2.10.8 allows remote HTTP servers to cause a denial of service (application crash) or possibly have unspecified other impact via an invalid chunk-size field in chunked transfer-coding data.

    Published: 28 Jan 2014
    10
    Critical

    CVE-2013-6490

    Last Modified: 11 Apr 2025

    The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Length header, which triggers a buffer overflow.

    Published: 28 Jan 2014
    2.1
    Low

    CVE-2014-1604

    Last Modified: 11 Apr 2025

    The parser cache functionality in parsergenerator.py in RPLY (aka python-rply) before 0.7.1 allows local users to spoof cache data by pre-creating a temporary rply-*.json file with a predictable name.

    Published: 28 Jan 2014
    3.3
    Low

    CVE-2014-1638

    Last Modified: 11 Apr 2025

    (1) debian/postrm and (2) debian/localepurge.config in localepurge before 0.7.3.2 use tempfile to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite arbitrary files via a symlink attack on the new filename.

    Published: 28 Jan 2014
    3.3
    Low

    CVE-2014-1639

    Last Modified: 11 Apr 2025

    syncevo/installcheck-local.sh in syncevolution before 1.3.99.7 uses mktemp to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite arbitrary files via a symlink attack on the new filename.

    Published: 28 Jan 2014
    3.3
    Low

    CVE-2014-1640

    Last Modified: 11 Apr 2025

    axiom-test.sh in axiom 20100701-1.1 uses tempfile to create a safe temporary file but appends a suffix to the original filename and writes to this new filename, which allows local users to overwrite arbitrary files via a symlink attack on the new filename.

    Published: 28 Jan 2014
    2.1
    Low

    CVE-2014-1831

    Last Modified: 12 Apr 2025

    Phusion Passenger before 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file.

    Published: 28 Jan 2014
    2.1
    Low

    CVE-2014-1832

    Last Modified: 12 Apr 2025

    Phusion Passenger 4.0.37 allows local users to write to certain files and directories via a symlink attack on (1) control_process.pid or a (2) generation-* file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1831.

    Published: 28 Jan 2014
    4.3
    Medium

    CVE-2013-6478

    Last Modified: 11 Apr 2025

    gtkimhtml.c in Pidgin before 2.10.8 does not properly interact with underlying library support for wide Pango layouts, which allows user-assisted remote attackers to cause a denial of service (application crash) via a long URL that is examined with a tooltip.

    Published: 28 Jan 2014
    5
    Medium

    CVE-2013-6479

    Last Modified: 11 Apr 2025

    util.c in libpurple in Pidgin before 2.10.8 does not properly allocate memory for HTTP responses that are inconsistent with the Content-Length header, which allows remote HTTP servers to cause a denial of service (application crash) via a crafted response.

    Published: 28 Jan 2014
    6.4
    Medium

    CVE-2013-6483

    Last Modified: 11 Apr 2025

    The XMPP protocol plugin in libpurple in Pidgin before 2.10.8 does not properly determine whether the from address in an iq reply is consistent with the to address in an iq request, which allows remote attackers to spoof iq traffic or cause a denial of service (NULL pointer dereference and application crash) via a crafted reply.

    Published: 28 Jan 2014
    10
    Critical

    CVE-2013-6838

    Last Modified: 11 Apr 2025

    An unspecified Enghouse Interactive Professional Services "addon product" in Enghouse Interactive IVR Pro (VIP2000) 9.0.3 (rel903), when using OpenVZ and fallback customization, uses the same SSH private key across different customers' installations, which allows remote attackers to gain privileges by leveraging knowledge of this key.

    Published: 28 Jan 2014
    5
    Medium

    CVE-2014-0020

    Last Modified: 11 Apr 2025

    The IRC protocol plugin in libpurple in Pidgin before 2.10.8 does not validate argument counts, which allows remote IRC servers to cause a denial of service (application crash) via a crafted message.

    Published: 28 Jan 2014
    2.1
    Low

    CVE-2014-0647

    Last Modified: 11 Apr 2025

    The Starbucks 2.6.1 application for iOS stores sensitive information in plaintext in the Crashlytics log file (/Library/Caches/com.crashlytics.data/com.starbucks.mystarbucks/session.clslog), which allows attackers to discover usernames, passwords, and e-mail addresses via an application that reads session.clslog.

    Published: 28 Jan 2014
    5
    Medium

    CVE-2012-5192

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to read arbitrary files via "''%2F" (dot dot encoded slash) sequences in the overlay_type parameter.

    Published: 28 Jan 2014
    7.1
    High

    CVE-2013-6747

    Last Modified: 11 Apr 2025

    IBM GSKit 7.x before 7.0.4.48 and 8.x before 8.0.50.16, as used in IBM Security Directory Server (ISDS) and Tivoli Directory Server (TDS), allows remote attackers to cause a denial of service (application crash or hang) via a malformed X.509 certificate chain.

    Published: 27 Jan 2014
    6.8
    Medium

    CVE-2013-6393

    Last Modified: 11 Apr 2025

    The yaml_parser_scan_tag_uri function in scanner.c in LibYAML before 0.1.5 performs an incorrect cast, which allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted tags in a YAML document, which triggers a heap-based buffer overflow.

    Published: 27 Jan 2014
    7.5
    High

    CVE-2013-4304

    Last Modified: 11 Apr 2025

    The CentralAuth extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 caches a valid CentralAuthUser object in the centralauth_User cookie even when a user has not successfully logged in, which allows remote attackers to bypass authentication without a password.

    Published: 26 Jan 2014
    4.3
    Medium

    CVE-2013-7142

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified oAuth API functions.

    Published: 26 Jan 2014
    5
    Medium

    CVE-2013-7298

    Last Modified: 11 Apr 2025

    query_params.cpp in cxxtools before 2.2.1 allows remote attackers to cause a denial of service (infinite recursion and crash) via an HTTP query that contains %% (double percent) characters.

    Published: 26 Jan 2014
    4.3
    Medium

    CVE-2013-7141

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to crafted "<%" tags.

    Published: 26 Jan 2014
    4.3
    Medium

    CVE-2013-7143

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.4.1 allows remote attackers to inject arbitrary web script or HTML via the title in a mail filter rule.

    Published: 26 Jan 2014
    4.3
    Medium

    CVE-2014-0794

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the JV Comment (com_jvcomment) component before 3.0.3 for Joomla! allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a comment.like action to index.php.

    Published: 26 Jan 2014
    4.3
    Medium

    CVE-2014-1607

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the EventCalendar module for Drupal 7.14 allows remote attackers to inject arbitrary web script or HTML via the year parameter to eventcalander/. NOTE: this issue has been disputed by the Drupal Security Team; it may be site-specific. If so, then this CVE will be REJECTed in the future

    Published: 26 Jan 2014
    5
    Medium

    CVE-2014-1664

    Last Modified: 11 Apr 2025

    The Citrix GoToMeeting application 5.0.799.1238 for Android logs HTTP requests containing sensitive information, which allows attackers to obtain user IDs, meeting details, and authentication tokens via an application that reads the system log file.

    Published: 26 Jan 2014
    4
    Medium

    CVE-2013-7140

    Last Modified: 11 Apr 2025

    XML External Entity (XXE) vulnerability in the CalDAV interface in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote authenticated users to read portions of arbitrary files via vectors related to the SAX builder and the WebDAV interface. NOTE: this issue has been labeled as both absolute path traversal and XXE, but the root cause may be XXE, since XXE can be exploited to conduct absolute path traversal and other attacks.

    Published: 26 Jan 2014
    5
    Medium

    CVE-2013-7299

    Last Modified: 11 Apr 2025

    framework/common/messageheaderparser.cpp in Tntnet before 2.2.1 allows remote attackers to obtain sensitive information via a header that ends in \n instead of \r\n, which prevents a null terminator from being added and causes Tntnet to include headers from other requests.

    Published: 26 Jan 2014
    4.3
    Medium

    CVE-2013-6853

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in clickstream.js in Y! Toolbar plugin for FireFox 3.1.0.20130813024103 for Mac, and 2.5.9.2013418100420 for Windows, allows remote attackers to inject arbitrary web script or HTML via a crafted URL that is stored by the victim.

    Published: 26 Jan 2014
    10
    Critical

    CVE-2013-7248

    Last Modified: 11 Apr 2025

    Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password for the roleDiag account, which allows remote attackers to gain root privileges, as demonstrated using a cmdWebCheckRole action in a TSA_REQUEST.

    Published: 26 Jan 2014
    6.5
    Medium

    CVE-2014-1671

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Dell KACE K1000 5.4.76847 and possibly earlier allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the macAddress element in a (1) getUploadPath or (2) getKBot SOAP request to service/kbot_service.php; the ID parameter to (3) userui/advisory_detail.php or (4) userui/ticket.php; and the (5) ORDER[] parameter to userui/ticket_list.php.

    Published: 26 Jan 2014
    5
    Medium

    CVE-2014-1673

    Last Modified: 11 Apr 2025

    Check Point Session Authentication Agent allows remote attackers to obtain sensitive information (user credentials) via unspecified vectors.

    Published: 26 Jan 2014
    3.6
    Low

    CVE-2013-5364

    Last Modified: 11 Apr 2025

    Secunia CSI Agent 6.0.0.15017 and earlier, 6.0.1.1007 and earlier, and 7.0.0.21 and earlier, when running on Red Hat Linux, uses world-readable and world-writable permissions for /etc/csia_config.xml, which allows local users to change CSI Agent configuration by modifying this file.

    Published: 26 Jan 2014
    9.8
    Critical

    CVE-2013-7137

    Last Modified: 11 Apr 2025

    The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.

    Published: 26 Jan 2014
    5
    Medium

    CVE-2013-7247

    Last Modified: 11 Apr 2025

    cgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers to discover sensitive information (user names and password hashes) via the cmdWebGetConfiguration action in a TSA_REQUEST.

    Published: 26 Jan 2014
    5
    Medium

    CVE-2014-1626

    Last Modified: 11 Apr 2025

    XML External Entity (XXE) vulnerability in MARC::File::XML module before 1.0.2 for Perl, as used in Evergreen, Koha, perl4lib, and possibly other products, allows context-dependent attackers to read arbitrary files via a crafted XML file.

    Published: 26 Jan 2014
    4
    Medium

    CVE-2014-1672

    Last Modified: 11 Apr 2025

    Check Point R75.47 Security Gateway and Management Server does not properly enforce Anti-Spoofing when the routing table is modified and the "Get - Interfaces with Topology" action is performed, which allows attackers to bypass intended access restrictions.

    Published: 26 Jan 2014
    4.3
    Medium

    CVE-2014-0673

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Cisco Video Surveillance 5000 HD IP Dome cameras allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug IDs CSCud10943 and CSCud10950.

    Published: 25 Jan 2014
    7.5
    High

    CVE-2014-0750

    Last Modified: 22 Aug 2025

    Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted HTTP request, aka ZDI-CAN-1622.

    Published: 25 Jan 2014
    5.5
    Medium

    CVE-2014-0678

    Last Modified: 11 Apr 2025

    The portal interface in Cisco Secure Access Control System (ACS) does not properly manage sessions, which allows remote authenticated users to hijack sessions and gain privileges via unspecified vectors, aka Bug ID CSCue65951.

    Published: 25 Jan 2014
    6.8
    Medium

    CVE-2014-0751

    Last Modified: 22 Aug 2025

    The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into the system. By modifying the source location, an attacker could send shell code to the CimWebServer which would deploy the nefarious files as part of any SCADA project. This could allow the attacker to execute arbitrary code.

    Published: 25 Jan 2014
    6.8
    Medium

    CVE-2014-1670

    Last Modified: 11 Apr 2025

    The Microsoft Bing application before 4.2.1 for Android allows remote attackers to install arbitrary APK files via vectors involving a crafted DNS response.

    Published: 25 Jan 2014
    2.1
    Low

    CVE-2013-1853

    Last Modified: 11 Apr 2025

    Almanah Diary 0.9.0 and 0.10.0 does not encrypt the database when closed, which allows local users to obtain sensitive information by reading the database.

    Published: 24 Jan 2014
    7.5
    High

    CVE-2014-1475

    Last Modified: 11 Apr 2025

    The OpenID module in Drupal 6.x before 6.30 and 7.x before 7.26 allows remote OpenID users to authenticate as other users via unspecified vectors.

    Published: 24 Jan 2014
    4
    Medium

    CVE-2014-1476

    Last Modified: 11 Apr 2025

    The Taxonomy module in Drupal 7.x before 7.26, when upgraded from an earlier version of Drupal, does not properly restrict access to unpublished content, which allows remote authenticated users to obtain sensitive information via a listing page.

    Published: 24 Jan 2014
    7.5
    High

    CVE-2013-5350

    Last Modified: 11 Apr 2025

    The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct PHP object injection attacks, and execute arbitrary PHP code, via a crafted serialized object.

    Published: 24 Jan 2014