CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2013-3482

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the rf_report_error function in ermapper_u.dll in Intergraph ERDAS ER Viewer before 13.0.1.1301 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long string in an ERS file.

    Published: 19 Jan 2014
    3.3
    Low

    CVE-2014-1208

    Last Modified: 11 Apr 2025

    VMware Workstation 9.x before 9.0.1, VMware Player 5.x before 5.0.1, VMware Fusion 5.x before 5.0.1, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1 allow guest OS users to cause a denial of service (VMX process disruption) by using an invalid port.

    Published: 17 Jan 2014
    4
    Medium

    CVE-2013-7295

    Last Modified: 11 Apr 2025

    Tor before 0.2.4.20, when OpenSSL 1.x is used in conjunction with a certain HardwareAccel setting on Intel Sandy Bridge and Ivy Bridge platforms, does not properly generate random numbers for (1) relay identity keys and (2) hidden-service identity keys, which might make it easier for remote attackers to bypass cryptographic protection mechanisms via unspecified vectors.

    Published: 17 Jan 2014
    4.3
    Medium

    CVE-2014-1207

    Last Modified: 11 Apr 2025

    VMware ESXi 4.0 through 5.1 and ESX 4.0 and 4.1 allow remote attackers to cause a denial of service (NULL pointer dereference) by intercepting and modifying Network File Copy (NFC) traffic.

    Published: 17 Jan 2014
    6.8
    Medium

    CVE-2014-1211

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in VMware vCloud Director 5.1.x before 5.1.3 allows remote attackers to hijack the authentication of arbitrary users for requests that trigger a logout.

    Published: 17 Jan 2014
    7.5
    High

    CVE-2014-0792

    Last Modified: 11 Apr 2025

    Sonatype Nexus 1.x and 2.x before 2.7.1 allows remote attackers to create arbitrary objects and execute arbitrary code via unspecified vectors related to unmarshalling of unintended Object types.

    Published: 17 Jan 2014
    6.8
    Medium

    CVE-2013-7204

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows remote attackers to hijack the authentication of administrators for requests that add arbitrary users.

    Published: 17 Jan 2014
    4.3
    Medium

    CVE-2013-7243

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1.2 and 3.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) post-menu field to edit.php or (2) Display name field to settings.php. NOTE: The Custom Permalink Structure and Email Address fields are already covered by CVE-2012-6621.

    Published: 17 Jan 2014
    2.1
    Low

    CVE-2014-2038

    Last Modified: 12 Apr 2025

    The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the same file.

    Published: 17 Jan 2014
    7.5
    High

    CVE-2012-6625

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the groupid parameter in an editgroup action.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2012-6632

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Vessio NetBill 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) file title to accounts/admin/index.php or (3) comment parameter in the support page to accounts/index2.php.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2012-6620

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the (1) tasks and (2) search views in Horde Kronolith H4 before 3.0.17 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2012-6622

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) groupid parameter in an editgroup action or (2) usergroup_id parameter in an edit_usergroup action.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2012-6623

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in fs-admin/wpf-add-forum.php in the ForumPress WP Forum Server plugin before 1.7.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the groupid parameter in an addforum action to wp-admin/admin.php.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2012-6624

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the SoundCloud Is Gold plugin 2.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the width parameter in a soundcloud_is_gold_player_preview action to wp-admin/admin-ajax.php.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2012-6627

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/test_mail.php in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2012-6628

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Newsletter Manager plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) xyz_em_campName to admin/create_campaign.php or (2) admin/edit_campaign.php, (3) xyz_em_email parameter to admin/edit_email.php, (4) xyz_em_exportbatchSize parameter to import_export.php, or (5) pagination limit in the Newsletter Manager options.

    Published: 16 Jan 2014
    6.8
    Medium

    CVE-2012-6629

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Newsletter Manager plugin 1.0.2 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change an email address or (2) conduct script insertion attacks. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2012-6630

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Media Library Categories plugin 1.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) bulk parameter to media-library-categories/add.php or (2) q parameter to media-library-categories/view.php.

    Published: 16 Jan 2014
    6.8
    Medium

    CVE-2012-6631

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in accounts/admin/index.php in Vessio NetBill 1.2 allows remote attackers to hijack the authentication of administrators for requests that add accounts via a new-client action.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2012-6621

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in GetSimple CMS 3.1, 3.1.2, 3.2.3, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Email Address or (2) Custom Permalink Structure fields in admin/settings.php; (3) path parameter to admin/upload.php; (4) err parameter to admin/theme.php; (5) error parameter to admin/pages.php; or (6) success or (7) err parameter to admin/index.php.

    Published: 16 Jan 2014
    7.5
    High

    CVE-2012-6626

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in verify-user.php in b2ePMS 1.0 allows remote attackers to execute arbitrary SQL commands via the username field.

    Published: 16 Jan 2014
    Unknown

    CVE-2013-3699

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 16 Jan 2014
    Unknown

    CVE-2013-3702

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-6344. Reason: This candidate is a duplicate of CVE-2013-6344. Notes: All CVE users should reference CVE-2013-6344 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Jan 2014
    Unknown

    CVE-2013-3698

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-6346. Reason: This candidate is a duplicate of CVE-2013-6346. Notes: All CVE users should reference CVE-2013-6346 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Jan 2014
    Unknown

    CVE-2013-3701

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-6345. Reason: This candidate is a duplicate of CVE-2013-6345. Notes: All CVE users should reference CVE-2013-6345 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2013-6325

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote attackers to cause a denial of service (resource consumption) via a crafted request to a web services endpoint.

    Published: 16 Jan 2014
    3.5
    Low

    CVE-2013-6330

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server 7.x before 7.0.0.31, when simpleFileServlet static file caching is enabled, allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 16 Jan 2014
    3.5
    Low

    CVE-2013-6725

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administrative Console in IBM WebSphere Application Server 7.x before 7.0.0.31, 8.0.x before 8.0.0.8, and 8.5.x before 8.5.5.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a crafted URL.

    Published: 16 Jan 2014
    4
    Medium

    CVE-2013-6687

    Last Modified: 11 Apr 2025

    The web portal in the Enterprise License Manager component in Cisco WebEx Meetings Server allows remote authenticated users to discover the cleartext administrative password by reading HTML source code, aka Bug ID CSCul33876.

    Published: 16 Jan 2014
    9
    Critical

    CVE-2014-0649

    Last Modified: 11 Apr 2025

    The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authorization requirements, which allows remote authenticated users to obtain superadmin access via a request to this interface, aka Bug ID CSCud75180.

    Published: 16 Jan 2014
    10
    Critical

    CVE-2014-0650

    Last Modified: 11 Apr 2025

    The web interface in Cisco Secure Access Control System (ACS) 5.x before 5.4 Patch 3 allows remote attackers to execute arbitrary operating-system commands via a request to this interface, aka Bug ID CSCue65962.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2014-0666

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Send Screen Capture implementation in Cisco Jabber 9.2(.1) and earlier on Windows allows remote attackers to upload arbitrary types of files, and consequently execute arbitrary code, via modified packets, aka Bug ID CSCug48056.

    Published: 16 Jan 2014
    6.3
    Medium

    CVE-2014-0667

    Last Modified: 11 Apr 2025

    The RMI interface in Cisco Secure Access Control System (ACS) does not properly enforce authorization requirements, which allows remote authenticated users to read arbitrary files via a request to this interface, aka Bug ID CSCud75169.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2013-6786

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a "URL redirection" issue that some sources list separately.

    Published: 16 Jan 2014
    10
    Critical

    CVE-2014-0648

    Last Modified: 11 Apr 2025

    The RMI interface in Cisco Secure Access Control System (ACS) 5.x before 5.5 does not properly enforce authentication and authorization requirements, which allows remote attackers to obtain administrative access via a request to this interface, aka Bug ID CSCud75187.

    Published: 16 Jan 2014
    5
    Medium

    CVE-2013-6642

    Last Modified: 11 Apr 2025

    Google Chrome through 32.0.1700.23 on Android allows remote attackers to spoof the address bar via unspecified vectors.

    Published: 16 Jan 2014
    7.5
    High

    CVE-2013-6646

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Web Workers implementation in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the shutting down of a worker process.

    Published: 16 Jan 2014
    7.5
    High

    CVE-2013-6641

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of the past names map of a FORM element.

    Published: 16 Jan 2014
    7.5
    High

    CVE-2013-6643

    Last Modified: 11 Apr 2025

    The OneClickSigninBubbleView::WindowClosing function in browser/ui/views/sync/one_click_signin_bubble_view.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows attackers to trigger a sync with an arbitrary Google account by leveraging improper handling of the closing of an untrusted signin confirm dialog.

    Published: 16 Jan 2014
    7.5
    High

    CVE-2013-6644

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 16 Jan 2014
    6.8
    Medium

    CVE-2013-6645

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the OnWindowRemovingFromRootWindow function in content/browser/web_contents/web_contents_view_aura.cc in Google Chrome before 32.0.1700.76 on Windows and before 32.0.1700.77 on Mac OS X and Linux allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving certain print-preview and tab-switch actions that interact with a speech input element.

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2014-1472

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Jan 2014
    6.8
    Medium

    CVE-2014-1473

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Enterprise Manager in McAfee Vulnerability Manager (MVM) 7.5.5 and earlier allow remote attackers to hijack the authentication of users for requests that modify HTML via unspecified vectors related to the "response web page."

    Published: 16 Jan 2014
    7.5
    High

    CVE-2014-0021

    Last Modified: 21 Nov 2024

    Chrony before 1.29.1 has traffic amplification in cmdmon protocol

    Published: 16 Jan 2014
    4.3
    Medium

    CVE-2014-0006

    Last Modified: 11 Apr 2025

    The TempURL middleware in OpenStack Object Storage (Swift) 1.4.6 through 1.8.0, 1.9.0 through 1.10.0, and 1.11.0 allows remote attackers to obtain secret URLs by leveraging an object name and a timing side-channel attack.

    Published: 16 Jan 2014
    6.4
    Medium

    CVE-2013-2826

    Last Modified: 11 Apr 2025

    WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager console rather than on the server, which allows remote attackers to bypass intended access restrictions and discover credentials via a crafted packet to TCP port 8130.

    Published: 15 Jan 2014
    7.5
    High

    CVE-2014-1466

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in CSP MySQL User Manager 2.3 allows remote attackers to execute arbitrary SQL commands via the login field of the login page.

    Published: 15 Jan 2014
    9.3
    Critical

    CVE-2013-2819

    Last Modified: 11 Apr 2025

    The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) update or (2) reprogramming action.

    Published: 15 Jan 2014
    10
    Critical

    CVE-2013-2820

    Last Modified: 11 Apr 2025

    The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.

    Published: 15 Jan 2014