CVE Feed

    Dashboard / CVE

    5.2
    Medium

    CVE-2013-4554

    Last Modified: 11 Apr 2025

    Xen 3.0.3 through 4.1.x (possibly 4.1.6.1), 4.2.x (possibly 4.2.3), and 4.3.x (possibly 4.3.1) does not properly prevent access to hypercalls, which allows local guest users to gain privileges via a crafted application running in ring 1 or 2.

    Published: 26 Nov 2013
    4.3
    Medium

    CVE-2013-6397

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in SolrResourceLoader in Apache Solr before 4.6 allows remote attackers to read arbitrary files via a .. (dot dot) or full pathname in the tr parameter to solr/select/, when the response writer (wt parameter) is set to XSLT. NOTE: this can be leveraged using a separate XXE (XML eXternal Entity) vulnerability to allow access to files across restricted network boundaries.

    Published: 26 Nov 2013
    5
    Medium

    CVE-2013-7294

    Last Modified: 11 Apr 2025

    The ikev2parent_inI1outR1 function in pluto/ikev2_parent.c in libreswan before 3.7 allows remote attackers to cause a denial of service (restart) via an IKEv2 I1 notification without a KE payload.

    Published: 26 Nov 2013
    4.3
    Medium

    CVE-2013-4573

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the ZeroRatedMobileAccess extension for MediaWiki 1.19.x before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to inject arbitrary web script or HTML via the "to" parameter to index.php.

    Published: 25 Nov 2013
    4.3
    Medium

    CVE-2013-6870

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 25 Nov 2013
    4.3
    Medium

    CVE-2012-6608

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in xmlservices/E_book.php in Elastix 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the Page parameter.

    Published: 25 Nov 2013
    7.8
    High

    CVE-2013-3922

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request.

    Published: 25 Nov 2013
    Unknown

    CVE-2013-6379

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4513. Reason: This candidate is a duplicate of CVE-2013-4513. Notes: All CVE users should reference CVE-2013-4513 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 25 Nov 2013
    2.1
    Low

    CVE-2013-4452

    Last Modified: 11 Apr 2025

    Red Hat JBoss Operations Network 3.1.2 uses world-readable permissions for the (1) server and (2) agent configuration files, which allows local users to obtain authentication credentials and other unspecified sensitive information by reading these files.

    Published: 25 Nov 2013
    2.6
    Low

    CVE-2013-4505

    Last Modified: 11 Apr 2025

    The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a denial of service (resource consumption) via a relative URL in a REPORT request.

    Published: 25 Nov 2013
    3.5
    Low

    CVE-2013-4558

    Last Modified: 11 Apr 2025

    The get_parent_resource function in repos.c in mod_dav_svn Apache HTTPD server module in Subversion 1.7.11 through 1.7.13 and 1.8.1 through 1.8.4, when built with assertions enabled and SVNAutoversioning is enabled, allows remote attackers to cause a denial of service (assertion failure and Apache process abort) via a non-canonical URL in a request, as demonstrated using a trailing /.

    Published: 25 Nov 2013
    4.6
    Medium

    CVE-2013-6412

    Last Modified: 11 Apr 2025

    The transform_save function in transform.c in Augeas 1.0.0 through 1.1.0 does not properly calculate the permission values when the umask contains a "7," which causes world-writable permissions to be used for new files and allows local users to modify the files via unspecified vectors.

    Published: 25 Nov 2013
    4.3
    Medium

    CVE-2013-6051

    Last Modified: 11 Apr 2025

    The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which allows remote attackers to cause a denial of service (bgpd crash) via a crafted BGP update.

    Published: 25 Nov 2013
    7.5
    High

    CVE-2013-6869

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the SRTT_GET_COUNT_BEFORE_KEY_RFC function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0862

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the process_frame_obj function in libavcodec/sanm.c in FFmpeg before 1.1.2 allow remote attackers to have an unspecified impact via crafted image dimensions in LucasArts Smush video data, which triggers an out-of-bounds array access.

    Published: 23 Nov 2013
    7.5
    High

    CVE-2013-4547

    Last Modified: 11 Apr 2025

    nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.

    Published: 23 Nov 2013
    8.5
    High

    CVE-2013-6859

    Last Modified: 11 Apr 2025

    SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 does not properly perform authorization, which allows remote authenticated users to gain privileges via unspecified vectors.

    Published: 23 Nov 2013
    9
    Critical

    CVE-2013-6863

    Last Modified: 11 Apr 2025

    SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to gain privileges via unspecified vectors.

    Published: 23 Nov 2013
    6.1
    Medium

    CVE-2013-6864

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to affect confidentiality, integrity, and availability via unspecified vectors.

    Published: 23 Nov 2013
    9
    Critical

    CVE-2013-6865

    Last Modified: 11 Apr 2025

    SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka CR732989.

    Published: 23 Nov 2013
    9
    Critical

    CVE-2013-6866

    Last Modified: 11 Apr 2025

    SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka CR736689.

    Published: 23 Nov 2013
    7.1
    High

    CVE-2013-6867

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 23 Nov 2013
    5
    Medium

    CVE-2013-0861

    Last Modified: 11 Apr 2025

    The avcodec_decode_audio4 function in libavcodec/utils.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.1 allows remote attackers to trigger memory corruption via vectors related to the channel layout.

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0863

    Last Modified: 11 Apr 2025

    Buffer overflow in the rle_decode function in libavcodec/sanm.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via crafted LucasArts Smush video data.

    Published: 23 Nov 2013
    10
    Critical

    CVE-2013-0864

    Last Modified: 11 Apr 2025

    The gif_copy_img_rect function in libavcodec/gifdec.c in FFmpeg before 1.1.2 performs an incorrect calculation for an "end pointer," which allows remote attackers to have an unspecified impact via crafted GIF data that triggers an out-of-bounds array access.

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0865

    Last Modified: 11 Apr 2025

    The vqa_decode_chunk function in libavcodec/vqavideo.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large (1) cbp0 or (2) cbpz chunk in Westwood Studios VQA Video file, which triggers an out-of-bounds write.

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0866

    Last Modified: 11 Apr 2025

    The aac_decode_init function in libavcodec/aacdec.c in FFmpeg before 1.0.4 and 1.1.x before 1.1.2 allows remote attackers to have an unspecified impact via a large number of channels in an AAC file, which triggers an out-of-bounds array access.

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0867

    Last Modified: 11 Apr 2025

    The decode_slice_header function in libavcodec/h264.c in FFmpeg before 1.1.2 does not properly check when the pixel format changes, which allows remote attackers to have unspecified impact via crafted H.264 video data, related to an out-of-bounds array access.

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0868

    Last Modified: 11 Apr 2025

    libavcodec/huffyuvdec.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted Huffyuv data, related to an out-of-bounds write and (1) unchecked return codes from the init_vlc function and (2) "len==0 cases."

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0869

    Last Modified: 11 Apr 2025

    The field_end function in libavcodec/h264.c in FFmpeg before 1.1.2 allows remote attackers to have an unspecified impact via crafted H.264 data, related to an SPS and slice mismatch and an out-of-bounds array access.

    Published: 23 Nov 2013
    5.8
    Medium

    CVE-2013-1058

    Last Modified: 11 Apr 2025

    maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.

    Published: 23 Nov 2013
    Unknown

    CVE-2013-1894

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2561. Reason: This candidate is a duplicate of CVE-2013-2561. Notes: All CVE users should reference CVE-2013-2561 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 23 Nov 2013
    4.9
    Medium

    CVE-2013-6861

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows local users to obtain sensitive information via unspecified vectors.

    Published: 23 Nov 2013
    7.8
    High

    CVE-2013-6862

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 23 Nov 2013
    3.3
    Low

    CVE-2013-4459

    Last Modified: 11 Apr 2025

    LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.

    Published: 23 Nov 2013
    6.8
    Medium

    CVE-2013-6860

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 23 Nov 2013
    7.8
    High

    CVE-2013-6868

    Last Modified: 11 Apr 2025

    SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows local users to obtain sensitive information via unspecified vectors.

    Published: 23 Nov 2013
    7.5
    High

    CVE-2013-4263

    Last Modified: 11 Apr 2025

    libavfilter in FFmpeg before 2.0.1 has unspecified impact and remote vectors related to a crafted "plane," which triggers an out-of-bounds heap write.

    Published: 23 Nov 2013
    10
    Critical

    CVE-2013-4265

    Last Modified: 11 Apr 2025

    The av_reallocp_array function in libavutil/mem.c in FFmpeg before 2.0.1 has an unspecified impact and remote vectors related to a "wrong return code" and a resultant NULL pointer dereference.

    Published: 23 Nov 2013
    10
    Critical

    CVE-2013-0872

    Last Modified: 11 Apr 2025

    The swr_init function in libswresample/swresample.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via an invalid or unsupported (1) input or (2) output channel layout, related to an out-of-bounds array access.

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0874

    Last Modified: 11 Apr 2025

    The (1) doubles2str and (2) shorts2str functions in libavcodec/tiff.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via a crafted TIFF image, related to an out-of-bounds array access.

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0876

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the (1) old_codec37 and (2) old_codec47 functions in libavcodec/sanm.c in FFmpeg before 1.1.3 allow remote attackers to have an unspecified impact via crafted LucasArts Smush data, which triggers an out-of-bounds array access.

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0877

    Last Modified: 11 Apr 2025

    The old_codec37 function in libavcodec/sanm.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted LucasArts Smush data that has a large size when decoded, related to an out-of-bounds array access.

    Published: 23 Nov 2013
    9.3
    Critical

    CVE-2013-0878

    Last Modified: 11 Apr 2025

    The advance_line function in libavcodec/targa.c in FFmpeg before 1.1.3 allows remote attackers to have an unspecified impact via crafted Targa image data, related to an out-of-bounds array access.

    Published: 23 Nov 2013
    4.3
    Medium

    CVE-2013-4264

    Last Modified: 11 Apr 2025

    The kempf_decode_tile function in libavcodec/g2meet.c in FFmpeg before 2.0.1 allows remote attackers to cause a denial of service (out-of-bounds heap write) via a G2M4 encoded file.

    Published: 23 Nov 2013
    4.3
    Medium

    CVE-2013-4589

    Last Modified: 11 Apr 2025

    The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.

    Published: 23 Nov 2013
    5
    Medium

    CVE-2010-3443

    Last Modified: 11 Apr 2025

    ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIVMSG message.

    Published: 23 Nov 2013
    4.3
    Medium

    CVE-2013-6858

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.

    Published: 23 Nov 2013
    6.8
    Medium

    CVE-2013-4407

    Last Modified: 11 Apr 2025

    HTTP::Body::Multipart in the HTTP-Body module for Perl (1.07 through 1.22, before 1.23) uses the part of the uploaded file's name after the first "." character as the suffix of a temporary file, which makes it easier for remote attackers to conduct attacks by leveraging subsequent behavior that may assume the suffix is well-formed.

    Published: 23 Nov 2013
    4.3
    Medium

    CVE-2013-3288

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability on the EMC RSA Data Protection Manager (DPM) appliance 3.2.x before 3.2.4.2 and 3.5.x before 3.5.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 22 Nov 2013