CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2013-6795

    Last Modified: 11 Apr 2025

    The Updater in Rackspace Openstack Windows Guest Agent for XenServer before 1.2.6.0 allows remote attackers to execute arbitrary code via a crafted serialized .NET object to TCP port 1984, which triggers the download and extraction of a ZIP file that overwrites the Agent service binary.

    Published: 24 Dec 2013
    6.8
    Medium

    CVE-2013-6403

    Last Modified: 11 Apr 2025

    The admin page in ownCloud before 5.0.13 allows remote attackers to bypass intended access restrictions via unspecified vectors, related to MariaDB.

    Published: 24 Dec 2013
    4.3
    Medium

    CVE-2013-6459

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.

    Published: 24 Dec 2013
    4.3
    Medium

    CVE-2013-7049

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earlier, allows remote attackers to cause a denial of service (crash) via a long string in a DH1080_INIT message.

    Published: 23 Dec 2013
    4
    Medium

    CVE-2013-7073

    Last Modified: 11 Apr 2025

    The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 does not check permissions, which allows remote authenticated editors to read arbitrary TYPO3 table columns via unspecified parameters.

    Published: 23 Dec 2013
    5.8
    Medium

    CVE-2013-7079

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 23 Dec 2013
    5.8
    Medium

    CVE-2013-7080

    Last Modified: 11 Apr 2025

    The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers to write to arbitrary fields in the configuration database table via crafted links, aka "Mass Assignment."

    Published: 23 Dec 2013
    6.8
    Medium

    CVE-2013-7102

    Last Modified: 11 Apr 2025

    Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-upload-sq_button.php in lib/admin/ in the OptimizePress theme before 1.61 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images_comingsoon, images_lncthumbs, or images_optbuttons in wp-content/uploads/optpress/, as exploited in the wild in November 2013.

    Published: 23 Dec 2013
    6.5
    Medium

    CVE-2013-7075

    Last Modified: 11 Apr 2025

    The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated backend users to unserialize arbitrary PHP objects, delete arbitrary files, and possibly have other unspecified impacts via an unspecified parameter, related to a "missing signature."

    Published: 23 Dec 2013
    7.2
    High

    CVE-2013-3709

    Last Modified: 11 Apr 2025

    WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.

    Published: 23 Dec 2013
    4.9
    Medium

    CVE-2013-7081

    Last Modified: 11 Apr 2025

    The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated editors to generate arbitrary HMAC signatures and bypass intended access restrictions via unspecified vectors.

    Published: 23 Dec 2013
    5
    Medium

    CVE-2013-6890

    Last Modified: 11 Apr 2025

    denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.

    Published: 23 Dec 2013
    5.4
    Medium

    CVE-2013-6979

    Last Modified: 11 Apr 2025

    The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, aka Bug ID CSCuj90227.

    Published: 23 Dec 2013
    3.5
    Low

    CVE-2013-5420

    Last Modified: 11 Apr 2025

    The IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to read log files by leveraging helpdesk privileges for a direct request.

    Published: 23 Dec 2013
    5
    Medium

    CVE-2013-2629

    Last Modified: 11 Apr 2025

    Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite actions in action.php.

    Published: 23 Dec 2013
    4.4
    Medium

    CVE-2013-5973

    Last Modified: 11 Apr 2025

    VMware ESXi 4.0 through 5.5 and ESX 4.0 and 4.1 allow local users to read or modify arbitrary files by leveraging the Virtual Machine Power User or Resource Pool Administrator role for a vCenter Server Add Existing Disk action with a (1) -flat, (2) -rdm, or (3) -rdmp filename.

    Published: 23 Dec 2013
    4.9
    Medium

    CVE-2013-4012

    Last Modified: 11 Apr 2025

    IBM WebSphere Portal 8.0.0.x before 8.0.0.1 CF09, when Content Template Catalog 4.0 is used, does not require administrative privileges for Portal Application Archive (PAA) file installation, which allows remote authenticated users to modify data or cause a denial of service via unspecified vectors.

    Published: 22 Dec 2013
    5
    Medium

    CVE-2013-6735

    Last Modified: 11 Apr 2025

    IBM WebSphere Portal 6.0.0.x through 6.0.0.1, 6.0.1.x through 6.0.1.7, 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x through 8.0.0.1 CF08 allows remote attackers to obtain sensitive Java Content Repository (JCR) information via a modified Web Content Manager (WCM) URL.

    Published: 22 Dec 2013
    4.9
    Medium

    CVE-2013-3705

    Last Modified: 11 Apr 2025

    The VBA32 AntiRootKit component for Novell Client 2 SP3 before IR5 on Windows allows local users to cause a denial of service (bugcheck and BSOD) via an IOCTL call for an invalid IOCTL.

    Published: 22 Dec 2013
    5
    Medium

    CVE-2013-6723

    Last Modified: 11 Apr 2025

    IBM WebSphere Portal 8.0.0.1 before CF09 does not properly handle references in compute="always" Web Content Manager (WCM) navigator components, which allows remote attackers to obtain sensitive component information via unspecified vectors.

    Published: 22 Dec 2013
    3.5
    Low

    CVE-2013-6745

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form.

    Published: 22 Dec 2013
    4.3
    Medium

    CVE-2013-5421

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote attackers to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form.

    Published: 22 Dec 2013
    4.3
    Medium

    CVE-2013-6316

    Last Modified: 11 Apr 2025

    IBM WebSphere Portal 7.0.0.x before 7.0.0.2 CF26 and 8.0.0.x before 8.0.0.1 CF09 does not properly handle content-selection changes during Taxonomy component rendering, which allows remote attackers to obtain sensitive property information in opportunistic circumstances by leveraging an error in a Web Content Manager (WCM) context processor.

    Published: 22 Dec 2013
    4.3
    Medium

    CVE-2013-6328

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Content Manager (WCM) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x before 8.0.0.1 CF09 allows remote attackers to inject arbitrary web script or HTML via vectors involving IFRAME elements.

    Published: 22 Dec 2013
    5
    Medium

    CVE-2013-7443

    Last Modified: 12 Apr 2025

    Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote attackers to cause a denial of service (crash) via crafted SQL statements.

    Published: 22 Dec 2013
    9.8
    Critical

    CVE-2013-7285

    Last Modified: 23 May 2025

    Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

    Published: 22 Dec 2013
    Unknown

    CVE-2013-6995

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Dec 2013
    4.7
    Medium

    CVE-2013-2822

    Last Modified: 11 Apr 2025

    NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically proximate attackers to cause a denial of service (driver crash and process restart) via crafted input over a serial line.

    Published: 21 Dec 2013
    4
    Medium

    CVE-2013-4044

    Last Modified: 11 Apr 2025

    IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote authenticated users to read application log files via a direct HTTP request.

    Published: 21 Dec 2013
    4.3
    Medium

    CVE-2013-4045

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Dec 2013
    5.8
    Medium

    CVE-2013-4046

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 21 Dec 2013
    2.1
    Low

    CVE-2013-4064

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9ARMFA.

    Published: 21 Dec 2013
    2.6
    Low

    CVE-2013-4065

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1, when ultra-light mode is enabled, allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPR TCLE98ZKRP.

    Published: 21 Dec 2013
    5
    Medium

    CVE-2013-4069

    Last Modified: 11 Apr 2025

    The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 21 Dec 2013
    5
    Medium

    CVE-2013-4070

    Last Modified: 11 Apr 2025

    The Portal application in IBM SPSS Collaboration and Deployment Services 4.2.1 before 4.2.1.3 IF3 and 5.0 before FP3 allows remote attackers to discover an internal password via unspecified vectors.

    Published: 21 Dec 2013
    4.3
    Medium

    CVE-2013-5411

    Last Modified: 11 Apr 2025

    IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote attackers to inject links and trigger unintended navigation or actions via unspecified vectors.

    Published: 21 Dec 2013
    4
    Medium

    CVE-2013-6978

    Last Modified: 11 Apr 2025

    The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain sensitive device information by reading "extraneous information" in HTML source code, aka Bug ID CSCuj39249.

    Published: 21 Dec 2013
    4.3
    Medium

    CVE-2013-4063

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.x before 8.5.3 FP6 and 9.0.x before 9.0.1 allows remote attackers to inject arbitrary web script or HTML via active content in an e-mail message, aka SPRs PTHN9AQMV7 and TCLE98ZKRP.

    Published: 21 Dec 2013
    3.5
    Low

    CVE-2013-5405

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.

    Published: 21 Dec 2013
    3.5
    Low

    CVE-2013-5406

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters, leading to improper interaction with the Windows MHTML protocol handler.

    Published: 21 Dec 2013
    4.9
    Medium

    CVE-2013-5407

    Last Modified: 11 Apr 2025

    IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not properly restrict use of FRAME elements, which allows remote authenticated users to bypass intended access restrictions or obtain sensitive information via a crafted web site, related to a "frame injection" issue.

    Published: 21 Dec 2013
    6.5
    Medium

    CVE-2013-5409

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 21 Dec 2013
    3.5
    Low

    CVE-2013-6196

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Autonomy Ultraseek 5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Dec 2013
    4.6
    Medium

    CVE-2012-4131

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in tar in Cisco NX-OS allows local users to access arbitrary files via crafted command-line arguments, aka Bug IDs CSCty07157, CSCty07159, CSCty07162, and CSCty07164.

    Published: 21 Dec 2013
    7.1
    High

    CVE-2013-2821

    Last Modified: 11 Apr 2025

    NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attackers to cause a denial of service (driver crash and process restart) via a crafted DNP3 TCP packet.

    Published: 21 Dec 2013
    4.3
    Medium

    CVE-2013-5413

    Last Modified: 11 Apr 2025

    IBM Sterling B2B Integrator 5.2 and Sterling File Gateway 2.2 do not invalidate a session upon a logout action, which allows remote attackers to bypass authentication by leveraging an unattended workstation.

    Published: 21 Dec 2013
    4.6
    Medium

    CVE-2012-4135

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in filesys in Cisco NX-OS 6.1(2) and earlier allows local users to access arbitrary files via crafted command-line arguments during a delete action, aka Bug IDs CSCty07270, CSCty07271, CSCty07273, and CSCty07275.

    Published: 21 Dec 2013
    4.3
    Medium

    CVE-2013-7002

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in mobile/php/translation/index.php in LiveZilla before 5.1.1.0 allows remote attackers to inject arbitrary web script or HTML via the g_language parameter.

    Published: 21 Dec 2013
    3.5
    Low

    CVE-2013-7074

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Content Editing Wizards in TYPO3 4.5.x before 4.5.32, 4.7.x before 4.7.17, 6.0.x before 6.0.12, 6.1.x before 6.1.7, and the development versions of 6.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters.

    Published: 21 Dec 2013
    4.3
    Medium

    CVE-2013-7076

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Extension Manager in TYPO3 4.5.x before 4.5.32 and 4.7.x before 4.7.17 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Dec 2013