CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2013-5197

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.

    Published: 18 Dec 2013
    6.8
    Medium

    CVE-2013-5225

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.

    Published: 18 Dec 2013
    6.8
    Medium

    CVE-2013-5195

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.

    Published: 18 Dec 2013
    6.8
    Medium

    CVE-2013-5199

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.

    Published: 18 Dec 2013
    6.8
    Medium

    CVE-2013-5228

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.

    Published: 18 Dec 2013
    3.3
    Low

    CVE-2013-5398

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5397.

    Published: 18 Dec 2013
    7.2
    High

    CVE-2013-5415

    Last Modified: 11 Apr 2025

    Buffer overflow in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges via unspecified vectors.

    Published: 18 Dec 2013
    7.2
    High

    CVE-2013-5416

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Rational ClearCase through 7.1.2.12, 8.0.0.x before 8.0.0.9, and 8.0.1.x before 8.0.1.2 allows local users to gain privileges via unknown vectors.

    Published: 18 Dec 2013
    2.1
    Low

    CVE-2013-5440

    Last Modified: 11 Apr 2025

    IBM InfoSphere Information Server 8.0, 8.1, 8.5, 8.7, and 9.1 allows local users to obtain sensitive information in opportunistic circumstances by leveraging the presence of file content after a failed installation.

    Published: 18 Dec 2013
    6.8
    Medium

    CVE-2013-5198

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple Safari before 6.1.1 and 7.x before 7.0.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-12-16-1.

    Published: 18 Dec 2013
    6.4
    Medium

    CVE-2013-5227

    Last Modified: 11 Apr 2025

    Apple Safari before 6.1.1 and 7.x before 7.0.1 allows remote attackers to bypass the Same Origin Policy and discover credentials by triggering autofill of subframe form fields.

    Published: 18 Dec 2013
    3.3
    Low

    CVE-2013-5397

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Webservice Axis Gateway in IBM Rational Focal Point 6.4 before devfix1, 6.4.1.3 before devfix1, 6.5.1 before devfix1, 6.5.2 before devfix4, 6.5.2.3 before devfix9, 6.6 before devfix5, 6.6.0.1 before devfix2, and 6.6.1 allows remote attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2013-5398.

    Published: 18 Dec 2013
    3.5
    Low

    CVE-2013-5402

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management, Maximo Asset Management Essentials, Maximo for Government, Maximo for Nuclear Power, Maximo for Transportation, Maximo for Life Sciences, Maximo for Oil and Gas, and Maximo for Utilities 7.1.x through 7.1.1.12, 7.1.2, 7.5 before 7.5.0.3 IFIX014, and 7.5.0.5 before IFIX003; SmartCloud Control Desk (SCCD) 7.5 before 7.5.0.3 IFIX014 and 7.5.0.5 before IFIX003; and Tivoli Asset Management for IT, Tivoli Service Request Manager, Maximo Service Desk, and Change and Configuration Management Database (CCMDB) 7.1.x through 7.1.1.12, 7.1.2, and 7.2.x through 7.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Dec 2013
    4
    Medium

    CVE-2013-5466

    Last Modified: 11 Apr 2025

    The XSLT library in IBM DB2 and DB2 Connect 9.5 through 10.5, and the DB2 pureScale Feature 9.8 for Enterprise Server Edition, allows remote authenticated users to cause a denial of service via unspecified vectors.

    Published: 18 Dec 2013
    5
    Medium

    CVE-2013-6701

    Last Modified: 11 Apr 2025

    The tNetTaskLimit process on the Transport Node Controller (TNC) on Cisco ONS 15454 devices with software 9.6 and earlier does not properly prioritize health pings, which allows remote attackers to cause a denial of service (watchdog timeout and TNC reset) via a flood of network traffic, aka Bug ID CSCud97155.

    Published: 18 Dec 2013
    4
    Medium

    CVE-2013-6437

    Last Modified: 12 Apr 2025

    The libvirt driver in OpenStack Compute (Nova) before 2013.2.2 and icehouse before icehouse-2 allows remote authenticated users to cause a denial of service (disk consumption) by creating and deleting instances with unique os_type settings, which triggers the creation of a new ephemeral disk backing file.

    Published: 18 Dec 2013
    2.1
    Low

    CVE-2013-4576

    Last Modified: 11 Apr 2025

    GnuPG 1.x before 1.4.16 generates RSA keys using sequences of introductions with certain patterns that introduce a side channel, which allows physically proximate attackers to extract RSA keys via a chosen-ciphertext attack and acoustic cryptanalysis during decryption. NOTE: applications are not typically expected to protect themselves from acoustic side-channel attacks, since this is arguably the responsibility of the physical device. Accordingly, issues of this type would not normally receive a CVE identifier. However, for this issue, the developer has specified a security policy in which GnuPG should offer side-channel resistance, and developer-specified security-policy violations are within the scope of CVE.

    Published: 18 Dec 2013
    4.3
    Medium

    CVE-2013-6882

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified form fields.

    Published: 17 Dec 2013
    6.8
    Medium

    CVE-2013-6883

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack the authentication of administrators for requests that modify the disk erase technique settings via unspecified vectors.

    Published: 17 Dec 2013
    4.3
    Medium

    CVE-2013-7129

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ThemeBeans Blooog theme 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the jQuery parameter to assets/js/jplayer.swf.

    Published: 17 Dec 2013
    4.7
    Medium

    CVE-2013-2816

    Last Modified: 11 Apr 2025

    The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line.

    Published: 17 Dec 2013
    5
    Medium

    CVE-2013-6193

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on HP LaserJet M1522n and M2727; LaserJet Pro 100, 300, 400, CM1415fnw, CP1*, M121*, M1536dnf, and P1*; Color LaserJet CM* and CP*; and TopShot LaserJet Pro M275 printers allows remote attackers to cause a denial of service via unknown vectors.

    Published: 17 Dec 2013
    3.5
    Low

    CVE-2013-6721

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Service Registry and Repository (WSRR) 7.5.x before 7.5.0.4 and 8.x through 8.0.0.2 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving widgets.

    Published: 17 Dec 2013
    4.3
    Medium

    CVE-2013-6733

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Application in the Classic Meeting Server in IBM Sametime 7.5.1.2 through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Dec 2013
    2.1
    Low

    CVE-2013-7127

    Last Modified: 11 Apr 2025

    Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist, which allows local users to obtain sensitive information by reading this file.

    Published: 17 Dec 2013
    2.1
    Low

    CVE-2013-7128

    Last Modified: 11 Apr 2025

    Valve Bug Reporter in the valve-bugreporter package 2.10+bsos1 in Valve SteamOS Beta stores cleartext credentials in a .valve-bugreporter.cfg file upon a Remember Credentials action, which allows local users to obtain sensitive information by reading this file.

    Published: 17 Dec 2013
    7.1
    High

    CVE-2013-2813

    Last Modified: 11 Apr 2025

    The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows remote attackers to cause a denial of service (reboot or link outage) via a crafted DNP3 TCP packet.

    Published: 17 Dec 2013
    6.8
    Medium

    CVE-2013-6038

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Trimble SketchUp Viewer 13.0.4124 allows remote attackers to execute arbitrary code via a crafted .SKP file.

    Published: 17 Dec 2013
    7.1
    High

    CVE-2013-2814

    Last Modified: 11 Apr 2025

    Cooper Power Systems Cybectec DNP3 Master OPC Server allows remote attackers to cause a denial of service (unhandled exception and process crash) via unspecified vectors.

    Published: 17 Dec 2013
    4.3
    Medium

    CVE-2013-6327

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the HTTP Option in IBM Sterling Connect:Enterprise 1.3 before 1.3.0.2 iFix 1 and 1.4 before 1.4.0.0 iFix 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cross-frame scripting" issue.

    Published: 17 Dec 2013
    7.8
    High

    CVE-2013-6329

    Last Modified: 11 Apr 2025

    IBM Global Security Kit (aka GSKit), as used in Content Manager OnDemand 8.5 and 9.0 and other products, allows remote attackers to cause a denial of service via a crafted handshake during resumption of an SSLv2 session.

    Published: 17 Dec 2013
    8
    High

    CVE-2013-6926

    Last Modified: 11 Apr 2025

    The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2) operator account.

    Published: 17 Dec 2013
    8.3
    High

    CVE-2013-6925

    Last Modified: 11 Apr 2025

    The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote attackers to hijack web sessions by predicting a session id value.

    Published: 17 Dec 2013
    5.8
    Medium

    CVE-2013-6966

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36031.

    Published: 17 Dec 2013
    6.8
    Medium

    CVE-2013-6192

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration before 9 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 17 Dec 2013
    4.3
    Medium

    CVE-2013-6191

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Dec 2013
    6.5
    Medium

    CVE-2013-4404

    Last Modified: 11 Apr 2025

    cumin in Red Hat Enterprise MRG Grid 2.4 does not properly enforce user roles, which allows remote authenticated users to bypass intended role restrictions and obtain sensitive information or perform privileged operations via unspecified vectors.

    Published: 17 Dec 2013
    6.8
    Medium

    CVE-2013-4405

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers to hijack the authentication of cumin users for unspecified requests.

    Published: 17 Dec 2013
    7.5
    High

    CVE-2013-4461

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator."

    Published: 17 Dec 2013
    6.4
    Medium

    CVE-2014-0071

    Last Modified: 12 Apr 2025

    PackStack in Red Hat OpenStack 4.0 does not enforce the default security groups when deployed to Neutron, which allows remote attackers to bypass intended access restrictions and make unauthorized connections.

    Published: 17 Dec 2013
    5.8
    Medium

    CVE-2013-6418

    Last Modified: 12 Apr 2025

    PyWBEM 0.7 and earlier uses a separate connection to validate X.509 certificates, which allows man-in-the-middle attackers to spoof a peer via an arbitrary certificate.

    Published: 17 Dec 2013
    5.8
    Medium

    CVE-2013-6444

    Last Modified: 12 Apr 2025

    PyWBEM 0.7 and earlier does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 17 Dec 2013
    5
    Medium

    CVE-2013-7112

    Last Modified: 11 Apr 2025

    The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 does not check for empty lines, which allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.

    Published: 17 Dec 2013
    5
    Medium

    CVE-2013-7113

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-bssgp.c in the BSSGP dissector in Wireshark 1.10.x before 1.10.4 incorrectly relies on a global variable, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 17 Dec 2013
    5
    Medium

    CVE-2013-7114

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the create_ntlmssp_v2_key function in epan/dissectors/packet-ntlmssp.c in the NTLMSSP v2 dissector in Wireshark 1.8.x before 1.8.12 and 1.10.x before 1.10.4 allow remote attackers to cause a denial of service (application crash) via a long domain name in a packet.

    Published: 17 Dec 2013
    7.8
    High

    CVE-2013-7172

    Last Modified: 21 Nov 2024

    Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.

    Published: 17 Dec 2013
    1.9
    Low

    CVE-2014-1446

    Last Modified: 11 Apr 2025

    The yam_ioctl function in drivers/net/hamradio/yam.c in the Linux kernel before 3.12.8 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCYAMGCFG ioctl call.

    Published: 17 Dec 2013
    4.3
    Medium

    CVE-2013-4414

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.

    Published: 17 Dec 2013
    4
    Medium

    CVE-2013-6422

    Last Modified: 11 Apr 2025

    The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

    Published: 17 Dec 2013
    5.8
    Medium

    CVE-2013-6456

    Last Modified: 12 Apr 2025

    The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shutdown or reboot host OS) via the (3) virDomainShutdown or (4) virDomainReboot API and a symlink attack on /dev/initctl in the container, related to "paths under /proc/$PID/root" and the virInitctlSetRunLevel function.

    Published: 17 Dec 2013