CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2013-6417

    Last Modified: 11 Apr 2025

    actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request that leverages (1) third-party Rack middleware or (2) custom Rack middleware. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-0155.

    Published: 3 Dec 2013
    Unknown

    CVE-2013-4417

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 Dec 2013
    Unknown

    CVE-2013-4528

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 Dec 2013
    Unknown

    CVE-2013-4543

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 2 Dec 2013
    4
    Medium

    CVE-2013-6695

    Last Modified: 11 Apr 2025

    The RBAC implementation in Cisco Secure Access Control System (ACS) does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to obtain sensitive information via a download action, as demonstrated by obtaining read access to the user database, aka Bug ID CSCuj39274.

    Published: 2 Dec 2013
    7.1
    High

    CVE-2013-6696

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software does not properly handle errors during the processing of DNS responses, which allows remote attackers to cause a denial of service (device reload) via a malformed response, aka Bug ID CSCuj28861.

    Published: 2 Dec 2013
    4.3
    Medium

    CVE-2012-0414

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11 SP1 allows remote attackers to inject arbitrary web script or HTML via an image name.

    Published: 2 Dec 2013
    4.4
    Medium

    CVE-2012-0420

    Last Modified: 11 Apr 2025

    zypp-refresh-wrapper in SUSE Zypper before 1.3.20 and 1.6.x before 1.6.166 allows local users to create files in arbitrary directories, or possibly have unspecified other impact, via a pathname in the ZYPP_LOCKFILE_ROOT environment variable.

    Published: 2 Dec 2013
    7.2
    High

    CVE-2012-0427

    Last Modified: 11 Apr 2025

    yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 allows local users to gain privileges via a crafted (1) file name or (2) directory name.

    Published: 2 Dec 2013
    7.2
    High

    CVE-2012-0426

    Last Modified: 11 Apr 2025

    Race condition in sap_suse_cluster_connector before 1.0.0-0.8.1 in SUSE Linux Enterprise for SAP Applications 11 SP2 allows local users to have an unspecified impact via vectors related to a tmp/ directory.

    Published: 2 Dec 2013
    7.8
    High

    CVE-2012-0425

    Last Modified: 11 Apr 2025

    LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows context-dependent attackers to obtain sensitive information by reading the (1) WIRELESS_WPA_PASSWORD or (2) WIRELESS_CLIENT_KEY_PASSWORD field.

    Published: 2 Dec 2013
    10
    Critical

    CVE-2012-0434

    Last Modified: 11 Apr 2025

    The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors.

    Published: 2 Dec 2013
    Unknown

    CVE-2013-3550

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0237. Reason: This candidate is a reservation duplicate of CVE-2013-0237. Notes: All CVE users should reference CVE-2013-0237 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Dec 2013
    4.3
    Medium

    CVE-2013-3707

    Last Modified: 11 Apr 2025

    The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intended SSL_free and SSL_shutdown calls for the close of a TCP connection, which allows remote attackers to cause a denial of service (service crash) by establishing many TCP connections to port 8009.

    Published: 1 Dec 2013
    4.7
    Medium

    CVE-2013-2818

    Last Modified: 11 Apr 2025

    The DNP Master Driver in Alstom e-terracontrol 3.5, 3.6, and 3.7 allows physically proximate attackers to cause a denial of service (infinite loop and DNP3 service disruption) via crafted input over a serial line.

    Published: 1 Dec 2013
    5
    Medium

    CVE-2013-3708

    Last Modified: 11 Apr 2025

    The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 1 Dec 2013
    6.4
    Medium

    CVE-2013-6718

    Last Modified: 11 Apr 2025

    The Advanced Management Module (AMM) with firmware 3.64B, 3.64C, and 3.64G for IBM BladeCenter systems allows remote attackers to discover account names and passwords via use of an unspecified interface.

    Published: 1 Dec 2013
    3.3
    Low

    CVE-2013-5636

    Last Modified: 11 Apr 2025

    Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by overwriting DVREM.EPM with a copy of itself after each few password guesses.

    Published: 30 Nov 2013
    5.8
    Medium

    CVE-2013-6918

    Last Modified: 11 Apr 2025

    The web interface on the Satechi travel router 1.5, when Wi-Fi is used for WAN access, exposes the console without authentication on the WAN IP address regardless of the "Web Management via WAN" setting, which allows remote attackers to bypass intended access restrictions via HTTP requests.

    Published: 30 Nov 2013
    3.3
    Low

    CVE-2013-5635

    Last Modified: 11 Apr 2025

    Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proximate attackers to bypass the device-locking protection mechanism by entering password guesses within multiple Unlock.exe processes that are running simultaneously.

    Published: 30 Nov 2013
    4.9
    Medium

    CVE-2013-6392

    Last Modified: 11 Apr 2025

    The genlock_dev_ioctl function in genlock.c in the Genlock driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted GENLOCK_IOC_EXPORT ioctl call.

    Published: 30 Nov 2013
    4.3
    Medium

    CVE-2013-6791

    Last Modified: 11 Apr 2025

    Microsoft Enhanced Mitigation Experience Toolkit (EMET) before 4.0 uses predictable addresses for hooked functions, which makes it easier for context-dependent attackers to defeat the ASLR protection mechanism via a return-oriented programming (ROP) attack.

    Published: 29 Nov 2013
    3.5
    Low

    CVE-2013-5448

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Right Click Plugin context menus in IBM Security QRadar SIEM 7.1 and 7.2 before 7.2 MR1 Patch 1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Nov 2013
    4.3
    Medium

    CVE-2013-5463

    Last Modified: 11 Apr 2025

    The WinCollect agent in IBM Security QRadar SIEM before 7.1.1.569824 allows remote attackers to bypass intended access restrictions by injecting a (1) DLL or (2) configuration file.

    Published: 29 Nov 2013
    3.5
    Low

    CVE-2013-6307

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Security QRadar SIEM 7.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 29 Nov 2013
    5
    Medium

    CVE-2013-6700

    Last Modified: 11 Apr 2025

    The SNMP module in Cisco IOS XR allows remote attackers to cause a denial of service (process reload) via a request for an unspecified MIB, aka Bug ID CSCuh43144.

    Published: 29 Nov 2013
    7.5
    High

    CVE-2013-4844

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Service Manager 7.11, 9.21, 9.30, 9.31, and 9.32, and ServiceCenter 6.2.8, allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 29 Nov 2013
    5.4
    Medium

    CVE-2013-6706

    Last Modified: 11 Apr 2025

    The Cisco Express Forwarding processing module in Cisco IOS XE allows remote attackers to cause a denial of service (device reload) via crafted MPLS packets that are not properly handled during IP header validation, aka Bug ID CSCuj23992.

    Published: 29 Nov 2013
    3.5
    Low

    CVE-2013-6322

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 8.0 before HF128 and 8.5 before HF93 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Nov 2013
    10
    Critical

    CVE-2013-5912

    Last Modified: 11 Apr 2025

    VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during an importFile action.

    Published: 28 Nov 2013
    4.7
    Medium

    CVE-2013-6885

    Last Modified: 11 Apr 2025

    The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue.

    Published: 28 Nov 2013
    6.4
    Medium

    CVE-2013-7038

    Last Modified: 11 Apr 2025

    The MHD_http_unescape function in libmicrohttpd before 0.9.32 might allow remote attackers to obtain sensitive information or cause a denial of service (crash) via unspecified vectors that trigger an out-of-bounds read.

    Published: 28 Nov 2013
    5.1
    Medium

    CVE-2013-7039

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the MHD_digest_auth_check function in libmicrohttpd before 0.9.32, when MHD_OPTION_CONNECTION_MEMORY_LIMIT is set to a large value, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long URI in an authentication header.

    Published: 28 Nov 2013
    7.8
    High

    CVE-2013-5065

    Last Modified: 22 Apr 2026

    NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

    Published: 27 Nov 2013
    3.5
    Low

    CVE-2013-3920

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Jahia xCM before 6.6.2 allows remote authenticated users to inject arbitrary web script or HTML via the "about me" field.

    Published: 27 Nov 2013
    5
    Medium

    CVE-2013-4617

    Last Modified: 11 Apr 2025

    Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.

    Published: 27 Nov 2013
    7.5
    High

    CVE-2013-5957

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in CRM/Core/Page/AJAX/Location.php in CiviCRM before 4.2.12, 4.3.x before 4.3.7, and 4.4.x before 4.4.beta4 allow remote attackers to execute arbitrary SQL commands via the _value parameter to (1) ajax/jqState or (2) ajax/jqcounty.

    Published: 27 Nov 2013
    4.3
    Medium

    CVE-2013-4624

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web script or HTML via (1) the site parameter to engines/manager.jsp, (2) the searchString parameter to administration/ in a search action, or the (3) username, (4) firstName, (5) lastName, (6) email, or (7) organization field to administration/ in a users action.

    Published: 27 Nov 2013
    4.3
    Medium

    CVE-2013-3394

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web interface in Cisco Prime Network Registrar 8.1 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted field, aka Bug ID CSCuh41429.

    Published: 27 Nov 2013
    3.5
    Low

    CVE-2013-4036

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Nov 2013
    5
    Medium

    CVE-2013-6712

    Last Modified: 11 Apr 2025

    The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.

    Published: 27 Nov 2013
    5
    Medium

    CVE-2013-3923

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in SavySoda WiFi HD Free before 7.0 allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request.

    Published: 26 Nov 2013
    7.5
    High

    CVE-2013-6873

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arbitrary SQL commands via the test_id parameter.

    Published: 26 Nov 2013
    9.3
    Critical

    CVE-2013-6874

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a long URL in a .m3u file.

    Published: 26 Nov 2013
    7.5
    High

    CVE-2013-6875

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.

    Published: 26 Nov 2013
    5
    Medium

    CVE-2013-4522

    Last Modified: 11 Apr 2025

    lib/filelib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 does not send "Cache-Control: private" HTTP headers, which allows remote attackers to obtain sensitive information by requesting a file that had been previously retrieved by a caching proxy server.

    Published: 26 Nov 2013
    3.5
    Low

    CVE-2013-4523

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in message/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via a crafted message.

    Published: 26 Nov 2013
    3.5
    Low

    CVE-2013-4525

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in mod/quiz/report/responses/responses_table.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to inject arbitrary web script or HTML via an answer to a text-based quiz question.

    Published: 26 Nov 2013
    6.8
    Medium

    CVE-2013-4524

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in repository/filesystem/lib.php in Moodle through 2.2.11, 2.3.x before 2.3.10, 2.4.x before 2.4.7, and 2.5.x before 2.5.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a path.

    Published: 26 Nov 2013
    5.2
    Medium

    CVE-2013-4553

    Last Modified: 11 Apr 2025

    The XEN_DOMCTL_getmemlist hypercall in Xen 3.4.x through 4.3.x (possibly 4.3.1) does not always obtain the page_alloc_lock and mm_rwlock in the same order, which allows local guest administrators to cause a denial of service (host deadlock).

    Published: 26 Nov 2013