CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-7184

    Last Modified: 11 Apr 2025

    Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted AVI file.

    Published: 24 Jan 2014
    4.3
    Medium

    CVE-2013-7316

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html.

    Published: 24 Jan 2014
    4.3
    Medium

    CVE-2013-7317

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in CS-Cart before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) settings_file or (2) data_file parameter to (a) ampie.swf, (b) amline.swf, or (c) amcolumn.swf.

    Published: 24 Jan 2014
    7.5
    High

    CVE-2014-1252

    Last Modified: 11 Apr 2025

    Double free vulnerability in Apple Pages 2.x before 2.1 and 5.x before 5.1 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Microsoft Word file.

    Published: 24 Jan 2014
    4.3
    Medium

    CVE-2014-0809

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Gapless Player SimZip (aka Simple Zip Viewer) application before 1.2.1 for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename.

    Published: 24 Jan 2014
    10
    Critical

    CVE-2013-5667

    Last Modified: 11 Apr 2025

    The Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to execute arbitrary commands via a get_userid action with shell metacharacters in the username parameter.

    Published: 24 Jan 2014
    7.8
    High

    CVE-2013-5668

    Last Modified: 11 Apr 2025

    The ADS/NT Support page on the Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to discover the administrator credentials by reading this page's cleartext content.

    Published: 24 Jan 2014
    7.8
    High

    CVE-2013-5669

    Last Modified: 11 Apr 2025

    The Thecus NAS server N8800 with firmware 5.03.01 uses cleartext credentials for administrative authentication, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 24 Jan 2014
    6.5
    Medium

    CVE-2013-7175

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Avanset Visual CertExam Manager 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) Title, (2) File name, or (3) Candidate Name field.

    Published: 24 Jan 2014
    5
    Medium

    CVE-2013-6030

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability on the Emerson Network Power Avocent MergePoint Unity 2016 (aka MPU2016) KVM switch with firmware 1.9.16473 allows remote attackers to read arbitrary files via unspecified vectors, as demonstrated by reading the /etc/passwd file.

    Published: 24 Jan 2014
    6.8
    Medium

    CVE-2014-0674

    Last Modified: 11 Apr 2025

    Cisco Video Surveillance Operations Manager (VSOM) does not require authentication for MySQL database connections, which allows remote attackers to obtain sensitive information, modify data, or cause a denial of service by leveraging network connectivity from a client system with a crafted host name, aka Bug ID CSCud10992.

    Published: 24 Jan 2014
    8.3
    High

    CVE-2014-1666

    Last Modified: 11 Apr 2025

    The do_physdev_op function in Xen 4.1.5, 4.1.6.1, 4.2.2 through 4.2.3, and 4.3.x does not properly restrict access to the (1) PHYSDEVOP_prepare_msix and (2) PHYSDEVOP_release_msix operations, which allows local PV guests to cause a denial of service (host or guest malfunction) or possibly gain privileges via unspecified vectors.

    Published: 24 Jan 2014
    7.5
    High

    CVE-2013-6933

    Last Modified: 11 Apr 2025

    The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2011.08.13 through 2013.11.25, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a (1) space or (2) tab character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow.

    Published: 23 Jan 2014
    7.5
    High

    CVE-2013-6934

    Last Modified: 11 Apr 2025

    The parseRTSPRequestString function in Live Networks Live555 Streaming Media 2013.11.26, as used in VideoLAN VLC Media Player, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a space character at the beginning of an RTSP message, which triggers an integer underflow, infinite loop, and buffer overflow. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6933.

    Published: 23 Jan 2014
    5.8
    Medium

    CVE-2014-1242

    Last Modified: 11 Apr 2025

    Apple iTunes before 11.1.4 uses HTTP for the iTunes Tutorials window, which allows man-in-the-middle attackers to spoof content by gaining control over the client-server data stream.

    Published: 23 Jan 2014
    2.1
    Low

    CVE-2013-5371

    Last Modified: 11 Apr 2025

    The client in IBM Tivoli Storage Manager (TSM) 6.3.1 and 6.4.0 on Windows does not preserve permissions of Resilient File System (ReFS) files across backup and restore operations, which allows local users to bypass intended access restrictions via standard filesystem operations.

    Published: 23 Jan 2014
    10
    Critical

    CVE-2014-0494

    Last Modified: 11 Apr 2025

    Adobe Digital Editions 2.0.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

    Published: 23 Jan 2014
    5.4
    Medium

    CVE-2013-7312

    Last Modified: 11 Apr 2025

    The OSPF implementation on Enterasys switches and routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

    Published: 23 Jan 2014
    5.4
    Medium

    CVE-2013-7308

    Last Modified: 11 Apr 2025

    The OSPF implementation on the D-Link DES-3810-28 switch with firmware R2.20.B017 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

    Published: 23 Jan 2014
    5.4
    Medium

    CVE-2013-7309

    Last Modified: 11 Apr 2025

    The OSPF implementation in Extreme Networks EXOS does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

    Published: 23 Jan 2014
    5.4
    Medium

    CVE-2013-7310

    Last Modified: 11 Apr 2025

    The OSPF implementation on Yamaha routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

    Published: 23 Jan 2014
    5.4
    Medium

    CVE-2013-7311

    Last Modified: 11 Apr 2025

    The OSPF implementation in Check Point Gaia OS R75.X and R76 and IPSO OS 6.2 R75.X and R76 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

    Published: 23 Jan 2014
    6.8
    Medium

    CVE-2013-7314

    Last Modified: 11 Apr 2025

    The OSPF implementation on NEC IP38X, IX1000, IX2000, and IX3000 routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

    Published: 23 Jan 2014
    5.4
    Medium

    CVE-2013-7306

    Last Modified: 11 Apr 2025

    The OSPF implementation on Brocade routers does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

    Published: 23 Jan 2014
    5.4
    Medium

    CVE-2013-7307

    Last Modified: 11 Apr 2025

    The OSPF implementation on the Brocade Vyatta vRouter with software before 6.6R1 does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

    Published: 23 Jan 2014
    5.4
    Medium

    CVE-2013-7313

    Last Modified: 11 Apr 2025

    The OSPF implementation in Juniper Junos through 13.x, JunosE, and ScreenOS through 6.3.x does not consider the possibility of duplicate Link State ID values in Link State Advertisement (LSA) packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

    Published: 23 Jan 2014
    4.3
    Medium

    CVE-2012-6447

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 5.0.0 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Jan 2014
    6.4
    Medium

    CVE-2014-0675

    Last Modified: 11 Apr 2025

    The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate across different customers' installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate's trust relationship, aka Bug ID CSCue07471.

    Published: 23 Jan 2014
    2.1
    Low

    CVE-2014-0979

    Last Modified: 11 Apr 2025

    The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.

    Published: 23 Jan 2014
    7.1
    High

    CVE-2013-7130

    Last Modified: 11 Apr 2025

    The i_create_images_and_backing (aka create_images_and_backing) method in libvirt driver in OpenStack Compute (Nova) Grizzly, Havana, and Icehouse, when using KVM live block migration, does not properly create all expected files, which allows attackers to obtain snapshot root disk contents of other users via ephemeral storage.

    Published: 23 Jan 2014
    4.4
    Medium

    CVE-2014-1642

    Last Modified: 11 Apr 2025

    The IRQ setup in Xen 4.2.x and 4.3.x, when using device passthrough and configured to support a large number of CPUs, frees certain memory that may still be intended for use, which allows local guest administrators to cause a denial of service (memory corruption and hypervisor crash) and possibly execute arbitrary code via vectors related to an out-of-memory error that triggers a (1) use-after-free or (2) double free.

    Published: 23 Jan 2014
    6.8
    Medium

    CVE-2013-7315

    Last Modified: 11 Apr 2025

    The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152. NOTE: this issue was SPLIT from CVE-2013-4152 due to different affected versions.

    Published: 23 Jan 2014
    5
    Medium

    CVE-2014-0677

    Last Modified: 11 Apr 2025

    The Label Distribution Protocol (LDP) functionality in Cisco NX-OS allows remote attackers to cause a denial of service (temporary LDP session outage) via LDP discovery traffic containing malformed Hello messages, aka Bug ID CSCul88851.

    Published: 22 Jan 2014
    7.1
    High

    CVE-2014-0660

    Last Modified: 11 Apr 2025

    Cisco TelePresence ISDN Gateway with software before 2.2(1.92) allows remote attackers to cause a denial of service (D-channel call outage) via a crafted Q.931 STATUS message, aka Bug ID CSCui50360.

    Published: 22 Jan 2014
    7.1
    High

    CVE-2014-0662

    Last Modified: 11 Apr 2025

    The SIP module in Cisco TelePresence Video Communication Server (VCS) before 8.1 allows remote attackers to cause a denial of service (process failure) via a crafted SDP message, aka Bug ID CSCue97632.

    Published: 22 Jan 2014
    6.8
    Medium

    CVE-2014-0676

    Last Modified: 11 Apr 2025

    Cisco NX-OS allows local users to bypass intended TACACS+ command restrictions via a series of multiple commands, aka Bug ID CSCum47367.

    Published: 22 Jan 2014
    4.3
    Medium

    CVE-2014-0806

    Last Modified: 11 Apr 2025

    The Sleipnir Mobile application 2.12.1 and earlier and Sleipnir Mobile Black Edition application 2.12.1 and earlier for Android provide Geolocation API data without verifying user consent, which allows remote attackers to obtain sensitive location information via a web site that makes API calls.

    Published: 22 Jan 2014
    6.4
    Medium

    CVE-2014-0807

    Last Modified: 11 Apr 2025

    data/class/pages/shopping/LC_Page_Shopping_Deliv.php in LOCKON EC-CUBE 2.4.4 and earlier, and 2.11.0 through 2.12.2, allows remote attackers to modify data via unspecified vectors.

    Published: 22 Jan 2014
    8.3
    High

    CVE-2014-0661

    Last Modified: 11 Apr 2025

    The System Status Collection Daemon (SSCD) in Cisco TelePresence System 500-37, 1000, 1300-65, and 3xxx before 1.10.2(42), and 500-32, 1300-47, TX1310 65, and TX9xxx before 6.0.4(11), allows remote attackers to execute arbitrary commands or cause a denial of service (stack memory corruption) via a crafted XML-RPC message, aka Bug ID CSCui32796.

    Published: 22 Jan 2014
    9.1
    Critical

    CVE-2014-0808

    Last Modified: 11 Apr 2025

    Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information by sending a crafted HTTP request.

    Published: 22 Jan 2014
    7.5
    High

    CVE-2014-1636

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Command School Student Management System 1.06.01 allow remote attackers to execute arbitrary SQL commands via the id parameter in an edit action to (1) admin_school_names.php, (2) admin_subjects.php, (3) admin_grades.php, (4) admin_terms.php, (5) admin_school_years.php, (6) admin_sgrades.php, (7) admin_media_codes_1.php, (8) admin_infraction_codes.php, (9) admin_generations.php, (10) admin_relations.php, (11) admin_titles.php, or (12) health_allergies.php in sw/.

    Published: 22 Jan 2014
    4.3
    Medium

    CVE-2013-2750

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 22 Jan 2014
    4.3
    Medium

    CVE-2013-7304

    Last Modified: 11 Apr 2025

    Check Point Endpoint Security MI Server through R73 3.0.0 HFA2.5 does not configure X.509 certificate validation for client devices, which allows man-in-the-middle attackers to spoof SSL servers by presenting an arbitrary certificate during a session established by a client.

    Published: 22 Jan 2014
    4.3
    Medium

    CVE-2013-7305

    Last Modified: 11 Apr 2025

    fpw.php in e107 through 1.0.4 does not check the user_ban field, which makes it easier for remote attackers to reset passwords by sending a pwsubmit request and leveraging access to the e-mail account of a banned user.

    Published: 22 Jan 2014
    5
    Medium

    CVE-2014-1637

    Last Modified: 11 Apr 2025

    Command School Student Management System 1.06.01 does not properly restrict access to sw/backup/backup_ray2.php, which allows remote attackers to download a database backup via a direct request.

    Published: 22 Jan 2014
    4
    Medium

    CVE-2014-0672

    Last Modified: 11 Apr 2025

    The Search and Play interface in Cisco MediaSense does not properly enforce authorization requirements, which allows remote authenticated users to download arbitrary recordings via a request to this interface.

    Published: 22 Jan 2014
    10
    Critical

    CVE-2013-6343

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp.

    Published: 22 Jan 2014
    5
    Medium

    CVE-2014-0669

    Last Modified: 11 Apr 2025

    The Wireless Session Protocol (WSP) feature in the Gateway GPRS Support Node (GGSN) component on Cisco ASR 5000 series devices allows remote attackers to bypass intended Top-Up payment restrictions via unspecified WSP packets, aka Bug ID CSCuh28371.

    Published: 22 Jan 2014
    4.3
    Medium

    CVE-2014-0670

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Search and Play interface in Cisco MediaSense allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCum16686.

    Published: 22 Jan 2014
    5.8
    Medium

    CVE-2014-0671

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Cisco MediaSense allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspecified parameter, aka Bug ID CSCum16749.

    Published: 22 Jan 2014