CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-6746

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in FileNet P8 Platform Documentation Installable Info Center 4.5.1 through 5.2.0 in IBM FileNet Business Process Manager 4.5.1 through 5.1.0, FileNet Content Manager 4.5.1 through 5.2.0, and Case Foundation 5.2.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Jan 2014
    9.8
    Critical

    CVE-2014-9746

    Last Modified: 12 Apr 2025

    The (1) t1_parse_font_matrix function in type1/t1load.c, (2) cid_parse_font_matrix function in cid/cidload.c, (3) t42_parse_font_matrix function in type42/t42parse.c, and (4) ps_parser_load_field function in psaux/psobjs.c in FreeType before 2.5.4 do not check return values, which allows remote attackers to cause a denial of service (uninitialized memory access and application crash) or possibly have unspecified other impact via a crafted font.

    Published: 22 Jan 2014
    7.5
    High

    CVE-2014-9747

    Last Modified: 12 Apr 2025

    The t42_parse_encoding function in type42/t42parse.c in FreeType before 2.5.4 does not properly update the current position for immediates-only mode, which allows remote attackers to cause a denial of service (infinite loop) via a Type42 font.

    Published: 22 Jan 2014
    10
    Critical

    CVE-2013-5986

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 has unknown impact and attack vectors, a different vulnerability than CVE-2013-5987.

    Published: 21 Jan 2014
    5
    Medium

    CVE-2013-1769

    Last Modified: 11 Apr 2025

    A certain hashing algorithm in Telepathy Gabble 0.16.x before 0.16.5 and 0.17.x before 0.17.3 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted message.

    Published: 21 Jan 2014
    7.2
    High

    CVE-2013-5987

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in NVIDIA graphics driver Release 331, 325, 319, 310, and 304 allows local users to bypass intended access restrictions for the GPU and gain privileges via unknown vectors.

    Published: 21 Jan 2014
    9.3
    Critical

    CVE-2013-1361

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Lenovo Bluetooth.

    Published: 21 Jan 2014
    4.3
    Medium

    CVE-2013-4884

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded sequences in a server response, which is not properly handled in the SuperScan HTML report.

    Published: 21 Jan 2014
    4
    Medium

    CVE-2012-2997

    Last Modified: 11 Apr 2025

    XML External Entity (XXE) vulnerability in sam/admin/vpe2/public/php/server.php in F5 BIG-IP 10.0.0 through 10.2.4 and 11.0.0 through 11.2.1 allows remote authenticated users to read arbitrary files via a crafted XML file.

    Published: 21 Jan 2014
    5.8
    Medium

    CVE-2013-4200

    Last Modified: 11 Apr 2025

    The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows remote attackers to bypass the allow_external_login_sites filtering property, redirect users to arbitrary web sites, and conduct phishing attacks via a space before a URL in the "next" parameter to acl_users/credentials_cookie_auth/require_login.

    Published: 21 Jan 2014
    6.8
    Medium

    CVE-2013-6922

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts via a crafted request to admin/access_control_user_add.php; (2) modify or (3) delete user accounts; (4) perform a factory reset; (5) perform a device reboot; or (6) add, (7) modify, or (8) delete shares and volumes.

    Published: 21 Jan 2014
    7.5
    High

    CVE-2013-2594

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref parameter.

    Published: 21 Jan 2014
    7.5
    High

    CVE-2013-7219

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! allows remote attackers to execute arbitrary SQL commands via the answer_id[] parameter.

    Published: 21 Jan 2014
    6.5
    Medium

    CVE-2013-6872

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a projectpdf action.

    Published: 21 Jan 2014
    7.5
    High

    CVE-2014-1618

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in UAEPD Shopping Cart Script allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) p_id parameter to products.php or id parameter to (3) page.php or (4) news.php.

    Published: 21 Jan 2014
    4.3
    Medium

    CVE-2013-6305

    Last Modified: 11 Apr 2025

    IBM Platform Symphony 5.2 before build 229037 and 6.1.0.1 before build 229073 uses the same credentials encryption key across different customers' installations, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging knowledge of this key.

    Published: 21 Jan 2014
    4.3
    Medium

    CVE-2014-1620

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in add.php in HIOX Guest Book (HGB) 5.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name1, (2) email, or (3) cmt parameter.

    Published: 21 Jan 2014
    5.8
    Medium

    CVE-2014-1452

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in lib/snmpagent.c in bsnmpd, as used in FreeBSD 8.3 through 10.0, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a crafted GETBULK PDU request.

    Published: 21 Jan 2014
    7.5
    High

    CVE-2014-1619

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Cubic CMS 5.1.1, 5.1.2, and 5.2 allow remote attackers to execute arbitrary SQL commands via the (1) resource_id or (2) version_id parameter to recursos/agent.php or (3) login or (4) pass parameter to login.usuario.

    Published: 21 Jan 2014
    5.8
    Medium

    CVE-2010-5293

    Last Modified: 11 Apr 2025

    wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.

    Published: 21 Jan 2014
    4.3
    Medium

    CVE-2010-5294

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the request_filesystem_credentials function in wp-admin/includes/file.php in WordPress before 3.0.2 allow remote servers to inject arbitrary web script or HTML by providing a crafted error message for a (1) FTP or (2) SSH connection attempt.

    Published: 21 Jan 2014
    4.3
    Medium

    CVE-2010-5295

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wp-admin/plugins.php in WordPress before 3.0.2 might allow remote attackers to inject arbitrary web script or HTML via a plugin's author field, which is not properly handled during a Delete Plugin action.

    Published: 21 Jan 2014
    4.9
    Medium

    CVE-2010-5296

    Last Modified: 11 Apr 2025

    wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.

    Published: 21 Jan 2014
    2.1
    Low

    CVE-2010-5297

    Last Modified: 11 Apr 2025

    WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.

    Published: 21 Jan 2014
    6.4
    Medium

    CVE-2012-6634

    Last Modified: 11 Apr 2025

    wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.

    Published: 21 Jan 2014
    4
    Medium

    CVE-2012-6635

    Last Modified: 11 Apr 2025

    wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by visiting a draft.

    Published: 21 Jan 2014
    2.1
    Low

    CVE-2013-5429

    Last Modified: 11 Apr 2025

    The Risk Based Access functionality in IBM Tivoli Federated Identity Manager (TFIM) 6.2.2 before FP9 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.2.2 before FP9 does not prevent reuse of One Time Password (OTP) tokens, which makes it easier for remote authenticated users to complete transactions by leveraging access to an already-used token.

    Published: 21 Jan 2014
    8.1
    High

    CVE-2013-6040

    Last Modified: 11 Apr 2025

    MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. Latest versions (4.0) of MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls have resolved the issue

    Published: 21 Jan 2014
    7.8
    High

    CVE-2014-0753

    Last Modified: 26 Aug 2025

    Stack-based buffer overflow in the SCADA server in Ecava IntegraXor before 4.1.4390 allows remote attackers to cause a denial of service (system crash) by triggering access to DLL code located in the IntegraXor directory.

    Published: 21 Jan 2014
    4
    Medium

    CVE-2011-5270

    Last Modified: 11 Apr 2025

    wp-admin/press-this.php in WordPress before 3.0.6 does not enforce the publish_posts capability requirement, which allows remote authenticated users to perform publish actions by leveraging the Contributor role.

    Published: 21 Jan 2014
    4.3
    Medium

    CVE-2012-6633

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.

    Published: 21 Jan 2014
    4.3
    Medium

    CVE-2013-4030

    Last Modified: 11 Apr 2025

    Integrated Management Module (IMM) 2 1.00 through 2.00 on IBM System X and Flex System servers supports SSL cipher suites with short keys, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack against (1) SSL or (2) TLS traffic.

    Published: 21 Jan 2014
    4.3
    Medium

    CVE-2013-6434

    Last Modified: 11 Apr 2025

    The remote-viewer in Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.3, when using a native SPICE client invocation method, initially makes insecure connections to the SPICE server, which allows man-in-the-middle attackers to spoof the SPICE server.

    Published: 21 Jan 2014
    3.3
    Low

    CVE-2014-1624

    Last Modified: 11 Apr 2025

    Race condition in the xdg.BaseDirectory.get_runtime_dir function in python-xdg 0.25 allows local users to overwrite arbitrary files by pre-creating /tmp/pyxdg-runtime-dir-fallback-victim to point to a victim-owned location, then replacing it with a symlink to an attacker-controlled location once the get_runtime_dir function is called.

    Published: 21 Jan 2014
    4
    Medium

    CVE-2014-0008

    Last Modified: 11 Apr 2025

    lib/adminlib.php in Moodle through 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 logs cleartext passwords, which allows remote authenticated administrators to obtain sensitive information by reading the Config Changes Report.

    Published: 20 Jan 2014
    5.5
    Medium

    CVE-2014-0009

    Last Modified: 11 Apr 2025

    course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request.

    Published: 20 Jan 2014
    6.8
    Medium

    CVE-2014-0010

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 allow remote attackers to hijack the authentication of administrators for requests that delete (1) categories or (2) fields.

    Published: 20 Jan 2014
    Unknown

    CVE-2013-2169

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 20 Jan 2014
    Unknown

    CVE-2013-2170

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 20 Jan 2014
    10
    Critical

    CVE-2013-3594

    Last Modified: 11 Apr 2025

    The SSH service on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device reset) or possibly execute arbitrary code by sending many packets to TCP port 22.

    Published: 20 Jan 2014
    6.8
    Medium

    CVE-2013-3595

    Last Modified: 11 Apr 2025

    The OpenManage web application 2.5 build 1.19 on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote authenticated users to cause a denial of service (device reset) via a direct request to an unspecified OSPF URL.

    Published: 20 Jan 2014
    7.8
    High

    CVE-2013-3606

    Last Modified: 11 Apr 2025

    The login page in the GoAhead web server on Dell PowerConnect 3348 1.2.1.3, 3524p 2.0.0.48, and 5324 2.0.1.4 switches allows remote attackers to cause a denial of service (device outage) via a long username.

    Published: 20 Jan 2014
    4.3
    Medium

    CVE-2014-0668

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the portal in Cisco Secure Access Control System (ACS) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCue65949.

    Published: 20 Jan 2014
    5
    Medium

    CVE-2013-6447

    Last Modified: 11 Apr 2025

    Multiple XML External Entity (XXE) vulnerabilities in the (1) ExecutionHandler, (2) PollHandler, and (3) SubscriptionHandler classes in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allow remote attackers to read arbitrary files and possibly have other impacts via a crafted XML file.

    Published: 20 Jan 2014
    5
    Medium

    CVE-2013-6448

    Last Modified: 11 Apr 2025

    The InterfaceGenerator handler in JBoss Seam Remoting in JBoss Seam 2 framework 2.3.1 and earlier, as used in JBoss Web Framework Kit, allows remote attackers to bypass the WebRemote annotation restriction and obtain information about arbitrary classes and methods on the server classpath via unspecified vectors.

    Published: 20 Jan 2014
    2.3
    Low

    CVE-2014-2573

    Last Modified: 12 Apr 2025

    The VMWare driver in OpenStack Compute (Nova) 2013.2 through 2013.2.2 does not properly put VMs into RESCUE status, which allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by requesting the VM be put into rescue and then deleting the image.

    Published: 20 Jan 2014
    9.8
    Critical

    CVE-2014-10072

    Last Modified: 21 Nov 2024

    In utils.c in zsh before 5.0.6, there is a buffer overflow when scanning very long directory paths for symbolic links.

    Published: 20 Jan 2014
    2.6
    Low

    CVE-2013-7078

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the errorAction method in the ActionController base class in the Extbase Framework in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6, when the Rewritten Property Mapper is enabled, allows remote attackers to inject arbitrary web script or HTML via unspecified input, which is returned in an error message. NOTE: this might be the same vulnerability as CVE-2013-7072.

    Published: 19 Jan 2014
    2.6
    Low

    CVE-2013-0244

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Drupal 6.x before 6.28 and 7.x before 7.19, when running with older versions of jQuery that are vulnerable to CVE-2011-4969, allows remote attackers to inject arbitrary web script or HTML via vectors involving unspecified Javascript functions that are used to select DOM elements.

    Published: 19 Jan 2014
    9.3
    Critical

    CVE-2013-3483

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted ERS file.

    Published: 19 Jan 2014