CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2013-6983

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the web interface in Cisco Unified Presence Server allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh35615.

    Published: 31 Dec 2013
    3.3
    Low

    CVE-2014-1447

    Last Modified: 11 Apr 2025

    Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.

    Published: 31 Dec 2013
    2.6
    Low

    CVE-2014-1690

    Last Modified: 12 Apr 2025

    The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet data is transmitted during use of the NAT mangle feature.

    Published: 31 Dec 2013
    6.8
    Medium

    CVE-2013-7209

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authentication of administrators for requests that change the user group permissions of arbitrary users via a groupsSave action.

    Published: 30 Dec 2013
    5.8
    Medium

    CVE-2013-5038

    Last Modified: 11 Apr 2025

    The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.

    Published: 30 Dec 2013
    5.4
    Medium

    CVE-2013-5039

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for requests that change the WiFi Security field to Deactivated via the WifiSecurity parameter.

    Published: 30 Dec 2013
    4.3
    Medium

    CVE-2013-5210

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the GUI login page in ADTRAN AOS before R10.8.1 on the NetVanta 7100 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Dec 2013
    2.9
    Low

    CVE-2013-5218

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.

    Published: 30 Dec 2013
    3.3
    Low

    CVE-2013-5219

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/passwd.

    Published: 30 Dec 2013
    6.1
    Medium

    CVE-2013-5220

    Last Modified: 11 Apr 2025

    goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data.

    Published: 30 Dec 2013
    3.5
    Low

    CVE-2013-5222

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 30 Dec 2013
    3.5
    Low

    CVE-2013-7231

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-5222.

    Published: 30 Dec 2013
    7.5
    High

    CVE-2013-7232

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands via unspecified input to the map or feature service.

    Published: 30 Dec 2013
    4.3
    Medium

    CVE-2013-4858

    Last Modified: 11 Apr 2025

    Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav.

    Published: 30 Dec 2013
    3.3
    Low

    CVE-2013-5037

    Last Modified: 11 Apr 2025

    The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages.

    Published: 30 Dec 2013
    6.8
    Medium

    CVE-2013-7233

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

    Published: 30 Dec 2013
    4.7
    Medium

    CVE-2014-1438

    Last Modified: 11 Apr 2025

    The restore_fpu_checking function in arch/x86/include/asm/fpu-internal.h in the Linux kernel before 3.12.8 on the AMD K7 and K8 platforms does not clear pending exceptions before proceeding to an EMMS instruction, which allows local users to cause a denial of service (task kill) or possibly gain privileges via a crafted application.

    Published: 30 Dec 2013
    9.3
    Critical

    CVE-2013-3846

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted CSpliceTreeEngine::InsertSplice object in an HTML document, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143 and CVE-2013-3161.

    Published: 29 Dec 2013
    10
    Critical

    CVE-2013-6189

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Archive Query Server in HP Application Information Optimizer (formerly HP Database Archiving) 6.2, 6.3, 6.4, and 7.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1666.

    Published: 29 Dec 2013
    5.2
    Medium

    CVE-2013-6197

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote authenticated users to execute arbitrary code via unknown vectors.

    Published: 29 Dec 2013
    4.3
    Medium

    CVE-2013-6198

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Dec 2013
    4.3
    Medium

    CVE-2013-2504

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 29 Dec 2013
    4.3
    Medium

    CVE-2013-5583

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Published: 29 Dec 2013
    4.3
    Medium

    CVE-2013-6808

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr field to pickup.php.

    Published: 28 Dec 2013
    5.8
    Medium

    CVE-2013-6812

    Last Modified: 11 Apr 2025

    The ONEDC app before 1.7 for iOS does not properly verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 28 Dec 2013
    7.2
    High

    CVE-2013-6886

    Last Modified: 11 Apr 2025

    RealVNC VNC 5.0.6 on Mac OS X, Linux, and UNIX allows local users to gain privileges via a crafted argument to the (1) vncserver, (2) vncserver-x11, or (3) Xvnc helper.

    Published: 28 Dec 2013
    6.5
    Medium

    CVE-2013-6929

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API input.

    Published: 28 Dec 2013
    7.6
    High

    CVE-2013-6932

    Last Modified: 11 Apr 2025

    Buffer overflow in IrfanView before 4.37, when a multibyte-character directory name is used, allows user-assisted remote attackers to execute arbitrary code via a crafted file that is incorrectly handled by the Thumbnail tooltips feature in the Thumbnails window.

    Published: 28 Dec 2013
    5.4
    Medium

    CVE-2013-6981

    Last Modified: 11 Apr 2025

    Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka Bug ID CSCul00709.

    Published: 28 Dec 2013
    4.3
    Medium

    CVE-2013-1096

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.

    Published: 28 Dec 2013
    5.8
    Medium

    CVE-2013-6006

    Last Modified: 11 Apr 2025

    Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.

    Published: 28 Dec 2013
    2.1
    Low

    CVE-2013-6181

    Last Modified: 11 Apr 2025

    EMC Watch4Net before 6.3 stores cleartext polled-device passwords in the installation repository, which allows local users to obtain sensitive information by leveraging repository privileges.

    Published: 28 Dec 2013
    7.2
    High

    CVE-2013-6182

    Last Modified: 11 Apr 2025

    Unquoted Windows search path vulnerability in EMC Replication Manager before 5.5 allows local users to gain privileges via a crafted application in a parent directory of an intended directory.

    Published: 28 Dec 2013
    7.5
    High

    CVE-2013-7149

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.

    Published: 28 Dec 2013
    Unknown

    CVE-2010-4174

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-3282. Reason: This candidate is a duplicate of CVE-2010-3282. Notes: All CVE users should reference CVE-2010-3282 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Dec 2013
    9.3
    Critical

    CVE-2010-1819

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in the Picture Viewer in Apple QuickTime before 7.6.8 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse (1) CoreVideo.dll, (2) CoreGraphics.dll, or (3) CoreAudioToolbox.dll that is located in the same folder as a .pic image file.

    Published: 27 Dec 2013
    7.1
    High

    CVE-2013-7338

    Last Modified: 12 Apr 2025

    Python before 3.3.4 RC1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a file size value larger than the size of the zip file to the (1) ZipExtFile.read, (2) ZipExtFile.read(n), (3) ZipExtFile.readlines, (4) ZipFile.extract, or (5) ZipFile.extractall function.

    Published: 27 Dec 2013
    10
    Critical

    CVE-2013-7217

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Zimbra Collaboration Server 7.2.5 and earlier, and 8.0.x through 8.0.5, has "critical" impact and unspecified vectors, a different vulnerability than CVE-2013-7091.

    Published: 26 Dec 2013
    2.1
    Low

    CVE-2013-4969

    Last Modified: 11 Apr 2025

    Puppet before 3.3.3 and 3.4 before 3.4.1 and Puppet Enterprise (PE) before 2.8.4 and 3.1 before 3.1.1 allows local users to overwrite arbitrary files via a symlink attack on unspecified files.

    Published: 26 Dec 2013
    5
    Medium

    CVE-2014-1829

    Last Modified: 12 Apr 2025

    Requests (aka python-requests) before 2.3.0 allows remote servers to obtain a netrc password by reading the Authorization header in a redirected request.

    Published: 25 Dec 2013
    5
    Medium

    CVE-2014-1830

    Last Modified: 12 Apr 2025

    Requests (aka python-requests) before 2.3.0 allows remote servers to obtain sensitive information by reading the Proxy-Authorization header in a redirected request.

    Published: 25 Dec 2013
    7.5
    High

    CVE-2013-7216

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.

    Published: 24 Dec 2013
    4.3
    Medium

    CVE-2012-6615

    Last Modified: 11 Apr 2025

    The ff_ass_split_override_codes function in libavcodec/ass_split.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a subtitle dialog without text.

    Published: 24 Dec 2013
    5
    Medium

    CVE-2012-6616

    Last Modified: 11 Apr 2025

    The mov_text_decode_frame function in libavcodec/movtextdec.c in FFmpeg before 1.0.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via crafted 3GPP TS 26.245 data.

    Published: 24 Dec 2013
    2.6
    Low

    CVE-2012-6618

    Last Modified: 11 Apr 2025

    The av_probe_input_buffer function in libavformat/utils.c in FFmpeg before 1.0.2, when running with certain -probesize values, allows remote attackers to cause a denial of service (crash) via a crafted MP3 file, possibly related to frame size or lack of sufficient "frames to estimate rate."

    Published: 24 Dec 2013
    2.1
    Low

    CVE-2013-6387

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.

    Published: 24 Dec 2013
    4.3
    Medium

    CVE-2013-6388

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.

    Published: 24 Dec 2013
    5
    Medium

    CVE-2013-4358

    Last Modified: 11 Apr 2025

    libavcodec/h264.c in FFmpeg before 0.11.4 allows remote attackers to cause a denial of service (crash) via vectors related to alternating bit depths in H.264 data.

    Published: 24 Dec 2013
    4.3
    Medium

    CVE-2011-5268

    Last Modified: 11 Apr 2025

    connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple failed SSL handshakes, a different vulnerability than CVE-2013-4550. NOTE: this issue was SPLIT from CVE-2013-4550 because it is a different type of issue.

    Published: 24 Dec 2013
    5.1
    Medium

    CVE-2013-4550

    Last Modified: 11 Apr 2025

    Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before stderr has been closed, which allows remote attackers to write to other sockets and have an unspecified impact via a failed SSL handshake, a different vulnerability than CVE-2011-5268. NOTE: some sources originally mapped this CVE to two different types of issues; this CVE has since been SPLIT, producing CVE-2011-5268.

    Published: 24 Dec 2013