CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2013-3140

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted CMarkup object, aka "Internet Explorer Use After Free Vulnerability."

    Published: 16 Dec 2013
    4.3
    Medium

    CVE-2013-4424

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Dec 2013
    7.2
    High

    CVE-2013-6441

    Last Modified: 11 Apr 2025

    The lxc-sshd template (templates/lxc-sshd.in) in LXC before 1.0.0.beta2 uses read-write permissions when mounting /sbin/init, which allows local users to gain privileges by modifying the init file.

    Published: 16 Dec 2013
    4.3
    Medium

    CVE-2013-5573

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HTML via the Description field in the user configuration.

    Published: 16 Dec 2013
    9.8
    Critical

    CVE-2014-9474

    Last Modified: 20 Apr 2025

    Buffer overflow in the mpfr_strtofr function in GNU MPFR before 3.1.2-p11 allows context-dependent attackers to have unspecified impact via vectors related to incorrect documentation for mpn_set_str.

    Published: 16 Dec 2013
    6.5
    Medium

    CVE-2013-6460

    Last Modified: 21 Nov 2024

    Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents

    Published: 15 Dec 2013
    6.5
    Medium

    CVE-2013-6461

    Last Modified: 21 Nov 2024

    Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits

    Published: 15 Dec 2013
    7.2
    High

    CVE-2013-7135

    Last Modified: 11 Apr 2025

    The Proc::Daemon module 0.14 for Perl uses world-writable permissions for a file that stores a process ID, which allows local users to have an unspecified impact by modifying this file.

    Published: 15 Dec 2013
    6.8
    Medium

    CVE-2013-4000

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.

    Published: 14 Dec 2013
    4.3
    Medium

    CVE-2013-4001

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.

    Published: 14 Dec 2013
    5.8
    Medium

    CVE-2013-6959

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul25557.

    Published: 14 Dec 2013
    4.3
    Medium

    CVE-2013-6963

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the registration component in Cisco WebEx Training Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36207.

    Published: 14 Dec 2013
    5.8
    Medium

    CVE-2013-6967

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the mobile-browser subsystem in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36020.

    Published: 14 Dec 2013
    5
    Medium

    CVE-2013-6968

    Last Modified: 11 Apr 2025

    Cisco WebEx Training Center provides different error messages for registration attempts depending on whether the e-mail address exists, which allows remote attackers to enumerate attendees via a series of requests, aka Bug ID CSCul36003.

    Published: 14 Dec 2013
    4.3
    Medium

    CVE-2013-6969

    Last Modified: 11 Apr 2025

    The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990.

    Published: 14 Dec 2013
    5
    Medium

    CVE-2013-6970

    Last Modified: 11 Apr 2025

    Cisco WebEx Meeting Center allows remote attackers to obtain sensitive information by reading verbose error messages within server responses, aka Bug ID CSCul35928.

    Published: 14 Dec 2013
    5.8
    Medium

    CVE-2013-6971

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul57140.

    Published: 14 Dec 2013
    5
    Medium

    CVE-2013-6972

    Last Modified: 11 Apr 2025

    Cisco WebEx Training Center allows remote attackers to discover session numbers, and bypass host approval for audio-conference attendance, by reading HTML source code, aka Bug ID CSCul57126.

    Published: 14 Dec 2013
    4.3
    Medium

    CVE-2013-6973

    Last Modified: 11 Apr 2025

    Cisco WebEx Training Center allows remote attackers to discover registration IDs via a crafted URL, aka Bug ID CSCul57121.

    Published: 14 Dec 2013
    4.3
    Medium

    CVE-2013-6960

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meeting Center allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36248.

    Published: 14 Dec 2013
    3.5
    Low

    CVE-2013-6964

    Last Modified: 11 Apr 2025

    Cisco WebEx Meeting Center allows remote authenticated users to bypass access control and inject content from a different WebEx site via unspecified vectors, aka Bug ID CSCul36197.

    Published: 14 Dec 2013
    2.1
    Low

    CVE-2013-3043

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the client in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.

    Published: 14 Dec 2013
    4.3
    Medium

    CVE-2013-4845

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability on HP Officejet Pro 8500 (aka A909) All-in-One printers allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Dec 2013
    4.3
    Medium

    CVE-2013-5438

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web server in IBM Flex System Manager (FSM) 1.1.0 through 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Dec 2013
    5
    Medium

    CVE-2013-6709

    Last Modified: 11 Apr 2025

    The registration component in Cisco WebEx Training Center provides the training-session URL before payment is completed, which allows remote attackers to bypass intended access restrictions and join an audio conference by entering credential fields from this URL, aka Bug ID CSCul57111.

    Published: 14 Dec 2013
    6.8
    Medium

    CVE-2013-6710

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Training Center allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCul25567.

    Published: 14 Dec 2013
    4.3
    Medium

    CVE-2013-6711

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the product-creation administrative page in Cisco WebEx Sales Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul25540.

    Published: 14 Dec 2013
    2.1
    Low

    CVE-2013-3042

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.

    Published: 14 Dec 2013
    4.3
    Medium

    CVE-2013-6961

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Collaboration Partner Access Console (CPAC) in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36237.

    Published: 14 Dec 2013
    4.3
    Medium

    CVE-2013-6962

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the mobile-browser subsystem in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36228.

    Published: 14 Dec 2013
    5
    Medium

    CVE-2013-6965

    Last Modified: 11 Apr 2025

    The registration component in Cisco WebEx Training Center provides the training-session URL before e-mail confirmation is completed, which allows remote attackers to bypass intended access restrictions and join an audio conference by entering credential fields from this URL, aka Bug ID CSCul36183.

    Published: 14 Dec 2013
    10
    Critical

    CVE-2013-7105

    Last Modified: 11 Apr 2025

    Buffer overflow in the Interstage HTTP Server log functionality, as used in Fujitsu Interstage Application Server 9.0.0, 9.1.0, 9.2.0, 9.3.1, and 10.0.0; and Interstage Studio 9.0.0, 9.1.0, 9.2.0, and 10.0.0, has unspecified impact and attack vectors related to "ihsrlog/rotatelogs."

    Published: 14 Dec 2013
    8.8
    High

    CVE-2013-6271

    Last Modified: 11 Apr 2025

    Android 4.0 through 4.3 allows attackers to bypass intended access restrictions and remove device locks via a crafted application that invokes the updateUnlockMethodAndFinish method in the com.android.settings.ChooseLockGeneric class with the PASSWORD_QUALITY_UNSPECIFIED option.

    Published: 14 Dec 2013
    6.8
    Medium

    CVE-2013-7069

    Last Modified: 11 Apr 2025

    ack 2.00 through 2.11_02 allows remote attackers to execute arbitrary code via a (1) --pager, (2) --regex, or (3) --output option in a .ackrc file in a directory to be searched.

    Published: 14 Dec 2013
    5.8
    Medium

    CVE-2013-7085

    Last Modified: 11 Apr 2025

    Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.

    Published: 14 Dec 2013
    5
    Medium

    CVE-2013-1364

    Last Modified: 11 Apr 2025

    The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.

    Published: 14 Dec 2013
    5
    Medium

    CVE-2013-6411

    Last Modified: 11 Apr 2025

    The HandleCrashedAircraft function in aircraft_cmd.cpp in OpenTTD 0.3.6 through 1.3.2 allows remote attackers to cause a denial of service (out-of-bounds read and crash) by crashing an aircraft outside of the map.

    Published: 14 Dec 2013
    9
    Critical

    CVE-2013-7104

    Last Modified: 11 Apr 2025

    McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) Command or (2) Script XML element. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands.

    Published: 14 Dec 2013
    9
    Critical

    CVE-2013-7103

    Last Modified: 11 Apr 2025

    McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in a (1) TestFile XML element or the (2) hostname. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands.

    Published: 14 Dec 2013
    5
    Medium

    CVE-2013-7093

    Last Modified: 11 Apr 2025

    SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vectors.

    Published: 13 Dec 2013
    7.5
    High

    CVE-2013-7094

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Dec 2013
    10
    Critical

    CVE-2013-7095

    Last Modified: 11 Apr 2025

    The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.

    Published: 13 Dec 2013
    7.5
    High

    CVE-2013-7096

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in SAP EMR Unwired allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 13 Dec 2013
    4.3
    Medium

    CVE-2013-4567

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via a \b (backspace) character in CSS.

    Published: 13 Dec 2013
    4.3
    Medium

    CVE-2013-4568

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in Sanitizer::checkCss in MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to conduct cross-site scripting (XSS) attacks via certain non-ASCII characters in CSS, as demonstrated using variations of "expression" containing (1) full width characters or (2) IPA extensions, which are converted and rendered by Internet Explorer.

    Published: 13 Dec 2013
    4.3
    Medium

    CVE-2013-4569

    Last Modified: 11 Apr 2025

    The CleanChanges extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3, when "Group changes by page in recent changes and watchlist" is enabled, allows remote attackers to obtain sensitive information (revision-deleted IPs) via the Recent Changes page.

    Published: 13 Dec 2013
    2.1
    Low

    CVE-2013-6956

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r17, 7.3 before 7.3r8, 7.4 before 7.4r6, and 8.0 before 8.0r1, when web rewrite is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Dec 2013
    4.3
    Medium

    CVE-2013-6957

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web administrative component in Juniper IDP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the ACM web server.

    Published: 13 Dec 2013
    7.1
    High

    CVE-2013-6958

    Last Modified: 11 Apr 2025

    Juniper NetScreen Firewall running ScreenOS 5.4, 6.2, or 6.3, when the Ping of Death screen is disabled, allows remote attackers to cause a denial of service via a crafted packet.

    Published: 13 Dec 2013
    5
    Medium

    CVE-2013-7091

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

    Published: 13 Dec 2013