CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2013-6935

    Last Modified: 11 Apr 2025

    Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the SourcePath value in a .wcf file.

    Published: 4 Dec 2013
    6.8
    Medium

    CVE-2013-6937

    Last Modified: 11 Apr 2025

    Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the name attribute of the cols element in a .wstyle file.

    Published: 4 Dec 2013
    4.3
    Medium

    CVE-2013-5449

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in workingSet.jsp in IBM Eclipse Help System (IEHS), as used in the installable InfoCenter component in IBM FileNet Content Manager 4.5.1, 5.0.0, 5.1.0, and 5.2.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 4 Dec 2013
    6.8
    Medium

    CVE-2013-6029

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code via a malformed .SVT file.

    Published: 4 Dec 2013
    5.5
    Medium

    CVE-2013-2133

    Last Modified: 11 Apr 2025

    The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class.

    Published: 4 Dec 2013
    4.3
    Medium

    CVE-2013-4492

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationData.new call.

    Published: 4 Dec 2013
    5
    Medium

    CVE-2013-6053

    Last Modified: 12 Apr 2025

    OpenJPEG 1.5.1 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read.

    Published: 4 Dec 2013
    5
    Medium

    CVE-2013-1447

    Last Modified: 11 Apr 2025

    OpenJPEG 1.3 and earlier allows remote attackers to cause a denial of service (memory consumption or crash) via unspecified vectors related to NULL pointer dereferences, division-by-zero, and other errors.

    Published: 4 Dec 2013
    5
    Medium

    CVE-2013-6052

    Last Modified: 11 Apr 2025

    OpenJPEG 1.3 and earlier allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based out-of-bounds read.

    Published: 4 Dec 2013
    7.5
    High

    CVE-2013-6638

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in runtime.cc in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a large typed array, related to the (1) Runtime_TypedArrayInitialize and (2) Runtime_TypedArrayInitializeFromArrayLike functions.

    Published: 4 Dec 2013
    7.5
    High

    CVE-2013-6640

    Last Modified: 11 Apr 2025

    The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds read) via JavaScript code that sets a variable to the value of an array element with a crafted index.

    Published: 4 Dec 2013
    7.5
    High

    CVE-2013-6045

    Last Modified: 11 Apr 2025

    Multiple heap-based buffer overflows in OpenJPEG 1.3 and earlier might allow remote attackers to execute arbitrary code via unspecified vectors.

    Published: 4 Dec 2013
    7.5
    High

    CVE-2013-6054

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in OpenJPEG 1.3 has unspecified impact and remote vectors, a different vulnerability than CVE-2013-6045.

    Published: 4 Dec 2013
    7.5
    High

    CVE-2013-6639

    Last Modified: 11 Apr 2025

    The DehoistArrayIndex function in hydrogen-dehoist.cc (aka hydrogen.cc) in Google V8 before 3.22.24.7, as used in Google Chrome before 31.0.1650.63, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via JavaScript code that sets the value of an array element with a crafted index.

    Published: 4 Dec 2013
    6.4
    Medium

    CVE-2013-6887

    Last Modified: 12 Apr 2025

    OpenJPEG 1.5.1 allows remote attackers to cause a denial of service via unspecified vectors that trigger NULL pointer dereferences, division-by-zero, and other errors.

    Published: 4 Dec 2013
    4.3
    Medium

    CVE-2013-7041

    Last Modified: 12 Apr 2025

    The pam_userdb module for Pam uses a case-insensitive method to compare hashed passwords, which makes it easier for attackers to guess the password via a brute force attack.

    Published: 4 Dec 2013
    6.1
    Medium

    CVE-2013-6705

    Last Modified: 11 Apr 2025

    The IP Device Tracking (IPDT) feature in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (IPDT AVL corruption and device reload) via a crafted sequence of ARP packets, aka Bug ID CSCuh38133.

    Published: 3 Dec 2013
    4.3
    Medium

    CVE-2013-6690

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Assurance component in Cisco Prime Collaboration allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCui92643, CSCui94038, and CSCui94161.

    Published: 3 Dec 2013
    7.1
    High

    CVE-2013-6703

    Last Modified: 11 Apr 2025

    The TLS/SSLv3 module on Cisco ONS 15454 controller cards allows remote attackers to cause a denial of service (card reset) via crafted (1) TLS or (2) SSLv3 packets, aka Bug ID CSCuh34787.

    Published: 3 Dec 2013
    7.1
    High

    CVE-2013-6704

    Last Modified: 11 Apr 2025

    Cisco IOS XE does not properly manage memory for TFTP UDP flows, which allows remote attackers to cause a denial of service (memory consumption) via TFTP (1) client or (2) server traffic, aka Bug IDs CSCuh09324 and CSCty42686.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4148

    Last Modified: 12 Apr 2025

    Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4149

    Last Modified: 12 Apr 2025

    Buffer overflow in virtio_net_load function in net/virtio-net.c in QEMU 1.3.0 through 1.7.x before 1.7.2 might allow remote attackers to execute arbitrary code via a large MAC table.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4150

    Last Modified: 12 Apr 2025

    The virtio_net_load function in hw/net/virtio-net.c in QEMU 1.5.0 through 1.7.x before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors in which the value of curr_queues is greater than max_queues, which triggers an out-of-bounds write.

    Published: 3 Dec 2013
    4.3
    Medium

    CVE-2013-4491

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted string that triggers generation of a fallback string by the i18n gem.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4526

    Last Modified: 12 Apr 2025

    Buffer overflow in hw/ide/ahci.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via vectors related to migrating ports.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4529

    Last Modified: 12 Apr 2025

    Buffer overflow in hw/pci/pcie_aer.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large log_num value in a savevm image.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4530

    Last Modified: 12 Apr 2025

    Buffer overflow in hw/ssi/pl022.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via crafted tx_fifo_head and rx_fifo_head values in a savevm image.

    Published: 3 Dec 2013
    7.8
    High

    CVE-2013-4532

    Last Modified: 21 Nov 2024

    Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4533

    Last Modified: 12 Apr 2025

    Buffer overflow in the pxa2xx_ssp_load function in hw/arm/pxa2xx.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted s->rx_level value in a savevm image.

    Published: 3 Dec 2013
    8.8
    High

    CVE-2013-4535

    Last Modified: 21 Nov 2024

    The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.

    Published: 3 Dec 2013
    7.8
    High

    CVE-2013-4536

    Last Modified: 21 Nov 2024

    An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4537

    Last Modified: 12 Apr 2025

    The ssi_sd_transfer function in hw/sd/ssi-sd.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted arglen value in a savevm image.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4539

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in the tsc210x_load function in hw/input/tsc210x.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted (1) precision, (2) nextprecision, (3) function, or (4) nextfunction value in a savevm image.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4540

    Last Modified: 12 Apr 2025

    Buffer overflow in scoop_gpio_handler_update in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a large (1) prev_level, (2) gpio_level, or (3) gpio_dir value in a savevm image.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4541

    Last Modified: 12 Apr 2025

    The usb_device_post_load function in hw/usb/bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, related to a negative setup_len or setup_index value.

    Published: 3 Dec 2013
    4
    Medium

    CVE-2013-4566

    Last Modified: 11 Apr 2025

    mod_nss 1.0.8 and earlier, when NSSVerifyClient is set to none for the server/vhost context, does not enforce the NSSVerifyClient setting in the directory context, which allows remote attackers to bypass intended access restrictions.

    Published: 3 Dec 2013
    6.8
    Medium

    CVE-2013-1978

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the read_xwd_cols function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an X Window System (XWD) image dump with more colors than color map entries.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-6399

    Last Modified: 12 Apr 2025

    Array index error in the virtio_load function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image.

    Published: 3 Dec 2013
    4.3
    Medium

    CVE-2013-6415

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.

    Published: 3 Dec 2013
    4.3
    Medium

    CVE-2013-6416

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.

    Published: 3 Dec 2013
    6.8
    Medium

    CVE-2013-6427

    Last Modified: 11 Apr 2025

    upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows man-in-the-middle attackers to execute arbitrary code by gaining control over the client-server data stream.

    Published: 3 Dec 2013
    5.8
    Medium

    CVE-2014-0194

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 3 Dec 2013
    6.8
    Medium

    CVE-2013-1913

    Last Modified: 11 Apr 2025

    Integer overflow in the load_image function in file-xwd.c in the X Window Dump (XWD) plug-in in GIMP 2.6.9 and earlier, when used with glib before 2.24, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large color entries value in an X Window System (XWD) image dump.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4151

    Last Modified: 12 Apr 2025

    The virtio_load function in virtio/virtio.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds write.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4527

    Last Modified: 12 Apr 2025

    Buffer overflow in hw/timer/hpet.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via vectors related to the number of timers.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4531

    Last Modified: 12 Apr 2025

    Buffer overflow in target-arm/machine.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a negative value in cpreg_vmstate_array_len in a savevm image.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4534

    Last Modified: 12 Apr 2025

    Buffer overflow in hw/intc/openpic.c in QEMU before 1.7.2 allows remote attackers to cause a denial of service or possibly execute arbitrary code via vectors related to IRQDest elements.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4538

    Last Modified: 12 Apr 2025

    Multiple buffer overflows in the ssd0323_load function in hw/display/ssd0323.c in QEMU before 1.7.2 allow remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via crafted (1) cmd_len, (2) row, or (3) col values; (4) row_start and row_end values; or (5) col_star and col_end values in a savevm image.

    Published: 3 Dec 2013
    7.5
    High

    CVE-2013-4542

    Last Modified: 12 Apr 2025

    The virtio_scsi_load_request function in hw/scsi/scsi-bus.c in QEMU before 1.7.2 might allow remote attackers to execute arbitrary code via a crafted savevm image, which triggers an out-of-bounds array access.

    Published: 3 Dec 2013
    5
    Medium

    CVE-2013-6414

    Last Modified: 11 Apr 2025

    actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.

    Published: 3 Dec 2013