CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-5072

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Outlook Web Access in Microsoft Exchange Server 2010 SP2 and SP3 and 2013 Cumulative Update 2 and 3 allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka "OWA XSS Vulnerability."

    Published: 11 Dec 2013
    5.8
    Medium

    CVE-2013-6391

    Last Modified: 11 Apr 2025

    The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

    Published: 11 Dec 2013
    5
    Medium

    CVE-2013-6419

    Last Modified: 11 Apr 2025

    Interaction error in OpenStack Nova and Neutron before Havana 2013.2.1 and icehouse-1 does not validate the instance ID of the tenant making a request, which allows remote tenants to obtain sensitive metadata by spoofing the device ID that is bound to a port, which is not properly handled by (1) api/metadata/handler.py in Nova and (2) the neutron-metadata-agent (agent/metadata/agent.py) in Neutron.

    Published: 11 Dec 2013
    4
    Medium

    CVE-2013-6426

    Last Modified: 11 Apr 2025

    The cloudformation-compatible API in OpenStack Orchestration API (Heat) before Havana 2013.2.1 and Icehouse before icehouse-2 does not properly enforce policy rules, which allows local in-instance users to bypass intended access restrictions and (1) create a stack via the CreateStack method or (2) update a stack via the UpdateStack method.

    Published: 11 Dec 2013
    8.3
    High

    CVE-2013-7043

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via the Password parameter to goform/RgSecurity; (2) reboot the device via the Restart parameter to goform/restart; (3) modify Wi-Fi settings, as demonstrated by the WpaPreSharedKey parameter to goform/wlanSecurity; or (4) modify parental controls via the ParentalPassword parameter to goform/RgParentalBasic.

    Published: 10 Dec 2013
    4.3
    Medium

    CVE-2012-3047

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web-wizard setup page on Cisco Scientific Atlanta D20 and D30 cable modems allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Dec 2013
    3.5
    Low

    CVE-2013-5404

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the search implementation in IBM Rational Quality Manager (RQM) 2.0 through 2.0.1.1, 3.x before 3.0.1.6 iFix 1, and 4.x before 4.0.5, as used in Rational Team Concert, Rational Requirements Composer, and other products, allows remote authenticated users to inject arbitrary web script or HTML via vectors involving an IFRAME element.

    Published: 10 Dec 2013
    9
    Critical

    CVE-2013-3622

    Last Modified: 11 Apr 2025

    Buffer overflow in logout.cgi in the Intelligent Platform Management Interface (IPMI) with firmware before 3.15 (SMT_X9_315) on Supermicro X9 generation motherboards allows remote authenticated users to execute arbitrary code via the SID parameter.

    Published: 10 Dec 2013
    10
    Critical

    CVE-2013-3623

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Management Interface (IPMI) with firmware before 3.15 (SMT_X9_315) on Supermicro X9 generation motherboards allow remote attackers to execute arbitrary code via the (1) sess_sid or (2) ACT parameter.

    Published: 10 Dec 2013
    4.3
    Medium

    CVE-2013-6224

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) a name in the call administrator feature, (2) unspecified vectors to the admins visitor information panel, or (3) a text message in a chat session, which is saved in the archive section.

    Published: 10 Dec 2013
    4.3
    Medium

    CVE-2013-3710

    Last Modified: 11 Apr 2025

    SUSE Lifecycle Management Server (SLMS) before 1.3.7 does not generate a new secret key when the service starts, which allows remote attackers to defeat intended cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere.

    Published: 10 Dec 2013
    6.9
    Medium

    CVE-2013-6840

    Last Modified: 11 Apr 2025

    Siemens COMOS before 9.2.0.8.1, 10.0 before 10.0.3.1.40, and 10.1 before 10.1.0.0.2 allows local users to gain database privileges via unspecified vectors.

    Published: 10 Dec 2013
    3.5
    Low

    CVE-2013-6237

    Last Modified: 11 Apr 2025

    The ISL Desktop plugin for Windows before 1.4.7 for ISL Light 3.5.4 and earlier allows remote authenticated users to obtain sensitive information by pasting the clipboard contents that have been copied by another user in the session.

    Published: 10 Dec 2013
    4.6
    Medium

    CVE-2013-7042

    Last Modified: 11 Apr 2025

    SUSE Lifecycle Management Server (SLMS) before 1.3.7 uses world-readable permissions for the secret keys, which allows local users to gain privileges via unspecified vectors.

    Published: 10 Dec 2013
    Unknown

    CVE-2013-2215

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 10 Dec 2013
    6.8
    Medium

    CVE-2013-5447

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary code via an XFDL form with a long fontname value.

    Published: 10 Dec 2013
    5
    Medium

    CVE-2013-6708

    Last Modified: 11 Apr 2025

    Cisco Cloud Portal 9.4 allows remote attackers to read files of unspecified types via a direct request, aka Bug IDs CSCuj08426 and CSCui60889.

    Published: 10 Dec 2013
    9.8
    Critical

    CVE-2013-6671

    Last Modified: 25 Nov 2025

    The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements.

    Published: 10 Dec 2013
    9.8
    Critical

    CVE-2013-5616

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the nsEventListenerManager::HandleEventSubType function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to mListeners event listeners.

    Published: 10 Dec 2013
    9.8
    Critical

    CVE-2013-5615

    Last Modified: 25 Nov 2025

    The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain typeset restrictions on the generation of GetElementIC typed array stubs, which has unspecified impact and remote attack vectors.

    Published: 10 Dec 2013
    9.8
    Critical

    CVE-2013-5613

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function.

    Published: 10 Dec 2013
    9.8
    Critical

    CVE-2013-5609

    Last Modified: 25 Nov 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 10 Dec 2013
    5
    Medium

    CVE-2013-7060

    Last Modified: 12 Apr 2025

    Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initialized in class scope.

    Published: 10 Dec 2013
    5.9
    Medium

    CVE-2013-6673

    Last Modified: 25 Nov 2025

    Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-middle attackers to spoof SSL servers in opportunistic circumstances via a valid certificate that is unacceptable to the user.

    Published: 10 Dec 2013
    9.3
    Critical

    CVE-2013-5331

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.

    Published: 10 Dec 2013
    10
    Critical

    CVE-2013-5610

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

    Published: 10 Dec 2013
    4.3
    Medium

    CVE-2013-5614

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.

    Published: 10 Dec 2013
    7.5
    High

    CVE-2013-6420

    Last Modified: 11 Apr 2025

    The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.

    Published: 10 Dec 2013
    5.5
    Medium

    CVE-2013-7061

    Last Modified: 12 Apr 2025

    Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.

    Published: 10 Dec 2013
    6.1
    Medium

    CVE-2013-7062

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x through 4.2.7, and 4.3 through 4.3.2, allow remote attackers to inject arbitrary web script or HTML via unspecified input in the (1) browser_id_manager or (2) OFS.Image method.

    Published: 10 Dec 2013
    9.3
    Critical

    CVE-2013-5332

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 10 Dec 2013
    9.8
    Critical

    CVE-2013-5618

    Last Modified: 25 Nov 2025

    Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.

    Published: 10 Dec 2013
    7.5
    High

    CVE-2013-5619

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.

    Published: 10 Dec 2013
    6.8
    Medium

    CVE-2013-6400

    Last Modified: 11 Apr 2025

    Xen 4.2.x and 4.3.x, when using Intel VT-d and a PCI device has been assigned, does not clear the flag that suppresses IOMMU TLB flushes when unspecified errors occur, which causes the TLB entries to not be flushed and allows local guest administrators to cause a denial of service (host crash) or gain privileges via unspecified vectors.

    Published: 10 Dec 2013
    4.3
    Medium

    CVE-2013-6672

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations.

    Published: 10 Dec 2013
    5.8
    Medium

    CVE-2013-5611

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.

    Published: 10 Dec 2013
    4.3
    Medium

    CVE-2013-5612

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 makes it easier for remote attackers to inject arbitrary web script or HTML by leveraging a Same Origin Policy violation triggered by lack of a charset parameter in a Content-Type HTTP header.

    Published: 10 Dec 2013
    6.8
    Medium

    CVE-2013-6180

    Last Modified: 11 Apr 2025

    EMC RSA Security Analytics (SA) 10.x before 10.3, and RSA NetWitness NextGen 9.8, does not ensure that SA Core requests originate from the SA REST UI, which allows remote attackers to bypass intended access restrictions by sending a Core request from a web browser or other unintended user agent.

    Published: 9 Dec 2013
    Unknown

    CVE-2013-6356

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue because of dependency on the victim's direct involvement in modifying the Windows registry to enable the attack. Notes: none

    Published: 9 Dec 2013
    2.1
    Low

    CVE-2013-3929

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the "Modify Events" permission to inject arbitrary web script or HTML via the handler parameter.

    Published: 9 Dec 2013
    6.8
    Medium

    CVE-2013-5355

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Sharetronix 3.1.1 allow remote attackers to hijack the authentication of administrators for requests that (1) change configuration settings or (2) create new administrative users via unspecified vectors.

    Published: 9 Dec 2013
    7.5
    High

    CVE-2013-6985

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows remote attackers to execute arbitrary SQL commands via the thisday parameter.

    Published: 9 Dec 2013
    7.5
    High

    CVE-2013-5354

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Sharetronix 3.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) fb_user_id or (2) tw_user_id parameter to signup.

    Published: 9 Dec 2013
    4.3
    Medium

    CVE-2013-6039

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in NagiosQL 3.2 SP2 allow remote attackers to inject arbitrary web script or HTML via the txtSearch parameter to (1) admin/hostdependencies.php, (2) admin/hosts.php, or other unspecified pages that allow search input, related to the search functionality in functions/content_class.php.

    Published: 9 Dec 2013
    7.5
    High

    CVE-2013-1349

    Last Modified: 11 Apr 2025

    Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP code via the modname parameter.

    Published: 9 Dec 2013
    7.5
    High

    CVE-2013-4376

    Last Modified: 11 Apr 2025

    The setgid wrapper libx2go-server-db-sqlite3-wrapper.c in X2Go Server before 4.0.0.2 allows remote attackers to execute arbitrary code via unspecified vectors, related to the path to libx2go-server-db-sqlite3-wrapper.pl.

    Published: 9 Dec 2013
    4
    Medium

    CVE-2013-6404

    Last Modified: 11 Apr 2025

    Quassel core (server daemon) in Quassel IRC before 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.

    Published: 9 Dec 2013
    6.8
    Medium

    CVE-2013-7008

    Last Modified: 11 Apr 2025

    The decode_slice_header function in libavcodec/h264.c in FFmpeg before 2.1 incorrectly relies on a certain droppable field, which allows remote attackers to cause a denial of service (deadlock) or possibly have unspecified other impact via crafted H.264 data.

    Published: 9 Dec 2013
    6.8
    Medium

    CVE-2013-7012

    Last Modified: 11 Apr 2025

    The get_siz function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not prevent attempts to use non-zero image offsets, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JPEG2000 data.

    Published: 9 Dec 2013
    6.8
    Medium

    CVE-2013-7013

    Last Modified: 11 Apr 2025

    The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted Go2Webinar data.

    Published: 9 Dec 2013