CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2013-4478

    Last Modified: 11 Apr 2025

    Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.

    Published: 7 Dec 2013
    6.8
    Medium

    CVE-2013-4479

    Last Modified: 11 Apr 2025

    lib/sup/message_chunks.rb in Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the content_type of an email attachment.

    Published: 7 Dec 2013
    4.3
    Medium

    CVE-2013-6050

    Last Modified: 11 Apr 2025

    Integer overflow in Links before 2.8 allows remote attackers to cause a denial of service (crash) via crafted HTML tables.

    Published: 7 Dec 2013
    6.2
    Medium

    CVE-2013-6409

    Last Modified: 11 Apr 2025

    Debian adequate before 0.8.1, when run by root with the --user option, allows local users to hijack the tty and possibly gain privileges via the TIOCSTI ioctl.

    Published: 7 Dec 2013
    7.5
    High

    CVE-2013-6410

    Last Modified: 11 Apr 2025

    nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file.

    Published: 7 Dec 2013
    4.9
    Medium

    CVE-2013-5455

    Last Modified: 11 Apr 2025

    IBM SmartCloud Provisioning 2.1 before FP3 IF0001 allows remote authenticated users to modify virtual-system deployment via deployer.virtualsystems CLI commands, as demonstrated by a deletion using a deployer.virtualsystems[#].delete command.

    Published: 7 Dec 2013
    4.3
    Medium

    CVE-2013-6707

    Last Modified: 11 Apr 2025

    Memory leak in the connection-manager implementation in Cisco Adaptive Security Appliance (ASA) Software 9.1(.3) and earlier allows remote attackers to cause a denial of service (multi-protocol management outage) by making multiple management session requests, aka Bug ID CSCug33233.

    Published: 7 Dec 2013
    4
    Medium

    CVE-2013-6999

    Last Modified: 11 Apr 2025

    The IsHandleEntrySecure function in win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2008 SP2 does not properly validate the tagPROCESSINFO pW32Job field, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted NtUserValidateHandleSecure call for an owned object. NOTE: the vendor reportedly disputes the significance of this report, stating that "it appears to be a local DOS ... we don't consider it a security vulnerability.

    Published: 7 Dec 2013
    6.8
    Medium

    CVE-2013-6635

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the editing implementation in Blink, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via JavaScript code that triggers removal of a node during processing of the DOM tree, related to CompositeEditCommand.cpp and ReplaceSelectionCommand.cpp.

    Published: 7 Dec 2013
    6.8
    Medium

    CVE-2013-6634

    Last Modified: 11 Apr 2025

    The OneClickSigninHelper::ShowInfoBarIfPossible function in browser/ui/sync/one_click_signin_helper.cc in Google Chrome before 31.0.1650.63 uses an incorrect URL during realm validation, which allows remote attackers to conduct session fixation attacks and hijack web sessions by triggering improper sync after a 302 (aka Found) HTTP status code.

    Published: 7 Dec 2013
    7.5
    High

    CVE-2013-6637

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.63 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 7 Dec 2013
    5
    Medium

    CVE-2013-7296

    Last Modified: 11 Apr 2025

    The JBIG2Stream::readSegments method in JBIG2Stream.cc in Poppler before 0.24.5 does not use the correct specifier within a format string, which allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted PDF file.

    Published: 7 Dec 2013
    4.3
    Medium

    CVE-2013-6636

    Last Modified: 11 Apr 2025

    The FrameLoader::notifyIfInitialDocumentAccessed function in core/loader/FrameLoader.cpp in Blink, as used in Google Chrome before 31.0.1650.63, makes an incorrect check for an empty document during presentation of a modal dialog, which allows remote attackers to spoof the address bar via vectors involving the document.write method.

    Published: 7 Dec 2013
    10
    Critical

    CVE-2013-6920

    Last Modified: 11 Apr 2025

    Siemens SINAMICS S/G controllers with firmware before 4.6.11 do not require authentication for FTP and TELNET sessions, which allows remote attackers to bypass intended access restrictions via TCP traffic to port (1) 21 or (2) 23.

    Published: 7 Dec 2013
    7.2
    High

    CVE-2013-1090

    Last Modified: 11 Apr 2025

    The SUSE horde5 package before 5.0.2-2.4.1 sets incorrect ownership for certain configuration files and directories including /etc/apache2/vhosts.d, which allows local wwwrun users to gain privileges via unspecified vectors.

    Published: 6 Dec 2013
    4
    Medium

    CVE-2013-5676

    Last Modified: 11 Apr 2025

    The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.

    Published: 6 Dec 2013
    5
    Medium

    CVE-2013-3921

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Easytime Studio Easy File Manager 1.1 for iOS allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) to the default URI.

    Published: 5 Dec 2013
    6
    Medium

    CVE-2013-6787

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6804

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Search module before 1.1.1 for Jamroom allows remote attackers to inject arbitrary web script or HTML via the search_string parameter to search/results/all/1/4.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6267

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.11.9 allow remote attackers to inject arbitrary web script or HTML via the (1) box parameter to messaging/messagebox.php, cidToEdit parameter to (2) adminregisteruser.php or (3) admin_user_course_settings.php in admin/, (4) module_id parameter to admin/module/module.php, or (5) offset parameter to admin/right/profile_list.php.

    Published: 5 Dec 2013
    7.5
    High

    CVE-2013-6341

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parameter to index.php.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6395

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6900

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6901

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0, when Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6902

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6903

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a schedule component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6905

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a phone component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6907

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 2.x and 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6908

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6909

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a report component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6910

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Ajax components in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    3.5
    Low

    CVE-2013-6911

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the bulletin-board component in Cybozu Garoon before 3.7.2, when Internet Explorer or Firefox is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    3.5
    Low

    CVE-2013-6912

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2, when Internet Explorer 6 through 9 is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    3.5
    Low

    CVE-2013-6914

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a calendar component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    3.5
    Low

    CVE-2013-6915

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    5
    Medium

    CVE-2013-6000

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Tattyan HP TOWN before 5_10_1 allows remote attackers to read arbitrary files via a .. (dot dot) in a request.

    Published: 5 Dec 2013
    6.5
    Medium

    CVE-2013-6001

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 5 Dec 2013
    5
    Medium

    CVE-2013-6002

    Last Modified: 11 Apr 2025

    The server in Cybozu Garoon before 3.7 SP1 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

    Published: 5 Dec 2013
    3.5
    Low

    CVE-2013-6003

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers via unspecified vectors.

    Published: 5 Dec 2013
    6.8
    Medium

    CVE-2013-6004

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6904

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a note component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6906

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon before 3.7.0, when Internet Explorer 6 through 8 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    3.5
    Low

    CVE-2013-6913

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a search component in Cybozu Garoon before 3.7.2, when Internet Explorer is used, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    4.3
    Medium

    CVE-2013-6916

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Yahoo! User Interface Library in Cybozu Garoon before 3.7.2, when Internet Explorer 9 or 10 or Chrome is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 5 Dec 2013
    5
    Medium

    CVE-2013-4549

    Last Modified: 11 Apr 2025

    QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (XEE) attack.

    Published: 5 Dec 2013
    7.5
    High

    CVE-2013-6945

    Last Modified: 11 Apr 2025

    The M2M Broker in OSEHRA VistA, as distributed before September 30, 2013, allows attackers to bypass authentication and authorization to perform doctor-only actions and read or modify patient records via unspecified vectors related to a "logic flaw."

    Published: 4 Dec 2013
    4.3
    Medium

    CVE-2013-2825

    Last Modified: 11 Apr 2025

    The DNP3 service in the Outstation component on Elecsys Director Gateway devices with kernel 2.6.32.11ael1 and earlier allows remote attackers to cause a denial of service (CPU consumption and communication outage) via crafted input.

    Published: 4 Dec 2013
    7.5
    High

    CVE-2013-6936

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.

    Published: 4 Dec 2013
    7.9
    High

    CVE-2013-3519

    Last Modified: 11 Apr 2025

    lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation.

    Published: 4 Dec 2013
    4.3
    Medium

    CVE-2013-6702

    Last Modified: 11 Apr 2025

    The management implementation on Cisco ONS 15454 controller cards with software 9.8 and earlier allows remote attackers to cause a denial of service (card reset) via crafted packets, aka Bug ID CSCtz50902.

    Published: 4 Dec 2013