CVE Feed

    Dashboard / CVE

    10
    Critical

    CVE-2013-6194

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1905.

    Published: 4 Jan 2014
    10
    Critical

    CVE-2013-2344

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1866.

    Published: 4 Jan 2014
    10
    Critical

    CVE-2013-2345

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1869.

    Published: 4 Jan 2014
    10
    Critical

    CVE-2013-2346

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1870.

    Published: 4 Jan 2014
    10
    Critical

    CVE-2013-2347

    Last Modified: 11 Apr 2025

    The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary commands or cause a denial of service via a crafted EXEC_BAR packet to TCP port 5555, aka ZDI-CAN-1885.

    Published: 4 Jan 2014
    10
    Critical

    CVE-2013-2348

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1892.

    Published: 4 Jan 2014
    10
    Critical

    CVE-2013-2349

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1896.

    Published: 4 Jan 2014
    10
    Critical

    CVE-2013-6195

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-2008.

    Published: 4 Jan 2014
    10
    Critical

    CVE-2013-2350

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1897.

    Published: 4 Jan 2014
    7.5
    High

    CVE-2013-7260

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow remote attackers to execute arbitrary code via a long (1) version number or (2) encoding declaration in the XML declaration of an RMP file, a different issue than CVE-2013-6877.

    Published: 3 Jan 2014
    7.5
    High

    CVE-2009-5137

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Mini-stream CastRipper 2.50.70 allows remote attackers to execute arbitrary code via a long URL in the [playlist] section in a .pls file, a different vector than CVE-2009-1667.

    Published: 2 Jan 2014
    5
    Medium

    CVE-2013-6953

    Last Modified: 11 Apr 2025

    BlogEngine.NET 2.8.0.0 and earlier allows remote attackers to read usernames and password hashes via a request for the sioc.axd file.

    Published: 2 Jan 2014
    4.3
    Medium

    CVE-2013-6991

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the WP-Cron Dashboard plugin 1.1.5 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the procname parameter to wp-admin/tools.php.

    Published: 2 Jan 2014
    4.3
    Medium

    CVE-2013-7257

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Codiad 2.0.7 allows remote attackers to inject arbitrary web script or HTML via the Project Name field.

    Published: 2 Jan 2014
    4.3
    Medium

    CVE-2013-7258

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in web2ldap 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "displaying group DN and entry data in group administration UI."

    Published: 2 Jan 2014
    6.8
    Medium

    CVE-2013-6992

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in askapache-firefox-adsense.php in the AskApache Firefox Adsense plugin 3.0 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the aafireadcode parameter to wp-admin/options-general.php.

    Published: 2 Jan 2014
    4.3
    Medium

    CVE-2013-7254

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Opsview before 4.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Jan 2014
    5.8
    Medium

    CVE-2013-7255

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Opsview before 4.4.2 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 2 Jan 2014
    6.8
    Medium

    CVE-2013-7256

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 2 Jan 2014
    4.3
    Medium

    CVE-2013-6993

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Ad-minister plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the key parameter in a delete action to wp-admin/tools.php.

    Published: 2 Jan 2014
    5
    Medium

    CVE-2013-7240

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.

    Published: 2 Jan 2014
    8.5
    High

    CVE-2013-5385

    Last Modified: 11 Apr 2025

    The OSPF implementation in IBM i 6.1 and 7.1, in z/OS on zSeries servers, and in Networking Operating System (aka NOS, formerly BLADE Operating System) does not properly validate Link State Advertisement (LSA) type 1 packets before performing operations on the LSA database, which allows remote attackers to cause a denial of service (routing disruption) or obtain sensitive packet information via a crafted LSA packet, a related issue to CVE-2013-0149.

    Published: 2 Jan 2014
    6.5
    Medium

    CVE-2013-7225

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in app/controllers/home_controller.rb in Fat Free CRM before 0.12.1 allow remote authenticated users to execute arbitrary SQL commands via (1) the homepage timeline feature or (2) the activity feature.

    Published: 2 Jan 2014
    3.5
    Low

    CVE-2013-7250

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the JsonBuilder implementation in ProjectForge before 5.3 allows remote authenticated users to inject arbitrary web script or HTML via an autocompletion string, related to web/core/JsonBuilder.java and web/wicket/autocompletion/PFAutoCompleteBehavior.java.

    Published: 2 Jan 2014
    Unknown

    CVE-2013-3282

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 2 Jan 2014
    Unknown

    CVE-2013-3283

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 2 Jan 2014
    Unknown

    CVE-2013-3284

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 2 Jan 2014
    Unknown

    CVE-2013-6179

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 2 Jan 2014
    Unknown

    CVE-2013-6183

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 2 Jan 2014
    Unknown

    CVE-2013-6184

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 2 Jan 2014
    Unknown

    CVE-2013-6185

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 2 Jan 2014
    Unknown

    CVE-2013-6186

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 2 Jan 2014
    Unknown

    CVE-2013-6187

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 2 Jan 2014
    5
    Medium

    CVE-2013-7222

    Last Modified: 11 Apr 2025

    config/initializers/secret_token.rb in Fat Free CRM before 0.12.1 has a fixed FatFreeCRM::Application.config.secret_token value, which makes it easier for remote attackers to spoof signed cookies by referring to the key in the source code.

    Published: 2 Jan 2014
    6.8
    Medium

    CVE-2013-7223

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Fat Free CRM before 0.12.1 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, related to the lack of a protect_from_forgery line in app/controllers/application_controller.rb.

    Published: 2 Jan 2014
    5
    Medium

    CVE-2013-7224

    Last Modified: 11 Apr 2025

    Fat Free CRM before 0.12.1 does not restrict JSON serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.json.

    Published: 2 Jan 2014
    5
    Medium

    CVE-2013-7249

    Last Modified: 11 Apr 2025

    Fat Free CRM before 0.12.1 does not restrict XML serialization, which allows remote attackers to obtain sensitive information via a direct request, as demonstrated by a request for users/1.xml, a different vulnerability than CVE-2013-7224.

    Published: 2 Jan 2014
    6.8
    Medium

    CVE-2013-7251

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in ProjectForge before 5.3 allow remote attackers to hijack the authentication of arbitrary users via vectors related to (1) web/admin/, (2) web/core/, (3) web/dialog/, (4) web/fibu/, (5) web/mobile/, (6) web/task/, or (7) web/wicket/.

    Published: 2 Jan 2014
    Unknown

    CVE-2013-3289

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2013. Notes: none

    Published: 2 Jan 2014
    3.5
    Low

    CVE-2011-5269

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ProjectForge before 3.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a validation message.

    Published: 2 Jan 2014
    6.8
    Medium

    CVE-2014-0791

    Last Modified: 11 Apr 2025

    Integer overflow in the license_read_scope_list function in libfreerdp/core/license.c in FreeRDP through 1.0.2 allows remote RDP servers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ScopeCount value in a Scope List in a Server License Request packet.

    Published: 2 Jan 2014
    10
    Critical

    CVE-2012-0262

    Last Modified: 11 Apr 2025

    op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter.

    Published: 31 Dec 2013
    10
    Critical

    CVE-2012-0264

    Last Modified: 11 Apr 2025

    op5 Monitor and op5 Appliance before 5.5.0 do not properly manage session cookies, which allows remote attackers to have an unspecified impact via unspecified vectors.

    Published: 31 Dec 2013
    6.1
    Medium

    CVE-2013-3572

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted client hostname.

    Published: 31 Dec 2013
    6.4
    Medium

    CVE-2013-3667

    Last Modified: 11 Apr 2025

    The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.

    Published: 31 Dec 2013
    10
    Critical

    CVE-2012-0261

    Last Modified: 11 Apr 2025

    license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the timestamp parameter for an install action.

    Published: 31 Dec 2013
    4
    Medium

    CVE-2012-0263

    Last Modified: 11 Apr 2025

    monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error messages that are triggered by (1) a malformed hoststatustypes parameter to status/service/all or (2) a crafted request to config.

    Published: 31 Dec 2013
    7.5
    High

    CVE-2013-6987

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot dot) in the (1) path parameter to file_delete.cgi or (2) folder_path parameter to file_share.cgi in webapi/FileStation/; (3) dlink parameter to fbdownload/; or unspecified parameters to (4) html5_upload.cgi, (5) file_download.cgi, (6) file_sharing.cgi, (7) file_MVCP.cgi, or (8) file_rename.cgi in webapi/FileStation/.

    Published: 31 Dec 2013
    4.3
    Medium

    CVE-2013-7241

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto before 1.4.5.4 allows remote attackers to inject arbitrary web script or HTML via the URI.

    Published: 31 Dec 2013
    6.5
    Medium

    CVE-2013-7242

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands via the tableprefix parameter.

    Published: 31 Dec 2013