CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2013-5997

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the SSH implementation on D-Link Japan DES-3800 devices with firmware before R4.50B58 allows remote authenticated users to cause a denial of service (device hang) via unknown vectors, a different vulnerability than CVE-2013-5998.

    Published: 22 Nov 2013
    5.8
    Medium

    CVE-2013-5999

    Last Modified: 11 Apr 2025

    Kingsoft KDrive Personal before 1.21.0.1880 on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 22 Nov 2013
    5
    Medium

    CVE-2013-6312

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Rational Service Tester 8.3.x and 8.5.x before 8.5.1 and Rational Performance Tester 8.3.x and 8.5.x before 8.5.1 allows remote attackers to read arbitrary files via unknown vectors.

    Published: 22 Nov 2013
    4.3
    Medium

    CVE-2013-6694

    Last Modified: 11 Apr 2025

    The IPSec implementation in Cisco IOS allows remote attackers to cause a denial of service (MTU change and tunnel-session drop) via crafted ICMP packets, aka Bug ID CSCul29918.

    Published: 22 Nov 2013
    5
    Medium

    CVE-2013-6699

    Last Modified: 11 Apr 2025

    The Control and Provisioning of Wireless Access Points (CAPWAP) protocol implementation on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to cause a denial of service via a crafted CAPWAP packet that triggers a buffer over-read, aka Bug ID CSCuh81880.

    Published: 22 Nov 2013
    7.8
    High

    CVE-2013-5998

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Web manager implementation on D-Link Japan DES-3800 devices with firmware before R4.50B58 allows remote attackers to cause a denial of service (device hang) via unknown vectors, a different vulnerability than CVE-2013-5997.

    Published: 22 Nov 2013
    4.3
    Medium

    CVE-2013-6698

    Last Modified: 11 Apr 2025

    The web interface on Cisco Wireless LAN Controller (WLC) devices does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCuf77821.

    Published: 22 Nov 2013
    4.3
    Medium

    CVE-2013-6342

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Tweet Blender plugin before 4.0.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tb_tab_index parameter to wp-admin/options-general.php.

    Published: 22 Nov 2013
    Unknown

    CVE-2013-6377

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 22 Nov 2013
    6.8
    Medium

    CVE-2013-6852

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication of administrators for requests that change an administrative password via the setPassword method.

    Published: 22 Nov 2013
    4.7
    Medium

    CVE-2013-2823

    Last Modified: 11 Apr 2025

    The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.

    Published: 22 Nov 2013
    6.3
    Medium

    CVE-2013-6692

    Last Modified: 11 Apr 2025

    Cisco IOS XE 3.8S(.2) and earlier does not properly use a DHCP pool during assignment of an IP address, which allows remote authenticated users to cause a denial of service (device reload) via an AAA packet that triggers an address requirement, aka Bug ID CSCuh04949.

    Published: 22 Nov 2013
    5.4
    Medium

    CVE-2013-6693

    Last Modified: 11 Apr 2025

    The MLDP implementation in Cisco IOS 15.3(3)S and earlier on 7600 routers, when many VRFs are configured, allows remote attackers to cause a denial of service (chunk corruption and device reload) by establishing many multicast flows, aka Bug ID CSCue22345.

    Published: 22 Nov 2013
    7.1
    High

    CVE-2013-2811

    Last Modified: 11 Apr 2025

    The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet.

    Published: 22 Nov 2013
    6.9
    Medium

    CVE-2013-6381

    Last Modified: 11 Apr 2025

    Buffer overflow in the qeth_snmp_command function in drivers/s390/net/qeth_core_main.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that is incompatible with the command-buffer size.

    Published: 22 Nov 2013
    4.4
    Medium

    CVE-2013-6378

    Last Modified: 11 Apr 2025

    The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation.

    Published: 22 Nov 2013
    4.7
    Medium

    CVE-2013-6380

    Last Modified: 11 Apr 2025

    The aac_send_raw_srb function in drivers/scsi/aacraid/commctrl.c in the Linux kernel through 3.12.1 does not properly validate a certain size value, which allows local users to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via an FSACTL_SEND_RAW_SRB ioctl call that triggers a crafted SRB command.

    Published: 22 Nov 2013
    6.9
    Medium

    CVE-2013-6383

    Last Modified: 11 Apr 2025

    The aac_compat_ioctl function in drivers/scsi/aacraid/linit.c in the Linux kernel before 3.11.8 does not require the CAP_SYS_RAWIO capability, which allows local users to bypass intended access restrictions via a crafted ioctl call.

    Published: 22 Nov 2013
    1.9
    Low

    CVE-2013-6384

    Last Modified: 11 Apr 2025

    (1) impl_db2.py and (2) impl_mongodb.py in OpenStack Ceilometer 2013.2 and earlier, when the logging level is set to INFO, logs the connection string from ceilometer.conf, which allows local users to obtain sensitive information (the DB2 or MongoDB password) by reading the log file.

    Published: 22 Nov 2013
    6.8
    Medium

    CVE-2013-4164

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allows context-dependent attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a string that is converted to a floating point value, as demonstrated using (1) the to_f method or (2) JSON.parse.

    Published: 22 Nov 2013
    4
    Medium

    CVE-2013-6382

    Last Modified: 11 Apr 2025

    Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_IOC_ATTRLIST_BY_HANDLE or (2) XFS_IOC_ATTRLIST_BY_HANDLE_32 ioctl call with a crafted length value, related to the xfs_attrlist_by_handle function in fs/xfs/xfs_ioctl.c and the xfs_compat_attrlist_by_handle function in fs/xfs/xfs_ioctl32.c.

    Published: 22 Nov 2013
    6.8
    Medium

    CVE-2013-6173

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote attackers to hijack the authentication of administrators for requests that perform administrative actions in (1) xAdmin or (2) xDashboard.

    Published: 21 Nov 2013
    4.9
    Medium

    CVE-2013-6833

    Last Modified: 11 Apr 2025

    The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.

    Published: 21 Nov 2013
    4.3
    Medium

    CVE-2013-5992

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 through 2.11.5 allows remote attackers to inject arbitrary web script or HTML by leveraging incorrect handling of error-message output.

    Published: 21 Nov 2013
    6.8
    Medium

    CVE-2013-5993

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.0 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors related to refusals.

    Published: 21 Nov 2013
    5.5
    Medium

    CVE-2013-5995

    Last Modified: 11 Apr 2025

    data/class/helper/SC_Helper_Address.php in the front-features implementation in LOCKON EC-CUBE 2.12.3 through 2.13.0 allows remote authenticated users to obtain sensitive information via unspecified vectors related to addresses.

    Published: 21 Nov 2013
    5.8
    Medium

    CVE-2013-6174

    Last Modified: 11 Apr 2025

    Multiple open redirect vulnerabilities in xAdmin in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters.

    Published: 21 Nov 2013
    4.3
    Medium

    CVE-2013-6175

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote attackers to inject arbitrary web script or HTML via unspecified input to a (1) xAdmin or (2) xDashboard form.

    Published: 21 Nov 2013
    6.5
    Medium

    CVE-2013-6176

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allow remote authenticated users to execute arbitrary SQL commands via unspecified input to a (1) xAdmin or (2) xDashboard form.

    Published: 21 Nov 2013
    3.5
    Low

    CVE-2013-6177

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in EMC Document Sciences xPression 4.1 SP1 before Patch 47, 4.2 before Patch 26, and 4.5 before Patch 05, as used in Documentum Edition, Enterprise Edition Publish Engine, and Enterprise Edition Compuset Engine, allows remote authenticated users to read arbitrary files by leveraging xDashboard access.

    Published: 21 Nov 2013
    4.3
    Medium

    CVE-2013-5991

    Last Modified: 11 Apr 2025

    The displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 through 2.11.5 allows remote attackers to obtain sensitive information by leveraging incorrect handling of error-log output.

    Published: 21 Nov 2013
    5
    Medium

    CVE-2013-5994

    Last Modified: 11 Apr 2025

    data/class/pages/mypage/LC_Page_Mypage_DeliveryAddr.php in LOCKON EC-CUBE 2.11.2 through 2.13.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.

    Published: 21 Nov 2013
    4.3
    Medium

    CVE-2013-5996

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in shopping/payment.tpl components in LOCKON EC-CUBE 2.11.0 through 2.13.0 allow remote attackers to inject arbitrary web script or HTML via crafted values.

    Published: 21 Nov 2013
    4.9
    Medium

    CVE-2013-6832

    Last Modified: 11 Apr 2025

    The nand_ioctl function in sys/dev/nand/nand_geom.c in the nand driver in the kernel in FreeBSD 10 and earlier does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.

    Published: 21 Nov 2013
    4.9
    Medium

    CVE-2013-6834

    Last Modified: 11 Apr 2025

    The ql_eioctl function in sys/dev/qlxgbe/ql_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.

    Published: 21 Nov 2013
    4
    Medium

    CVE-2013-4485

    Last Modified: 11 Apr 2025

    389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authenticated users to cause a denial of service (crash) via multiple @ characters in a GER attribute list in a search request.

    Published: 21 Nov 2013
    5.5
    Medium

    CVE-2013-6373

    Last Modified: 11 Apr 2025

    The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

    Published: 21 Nov 2013
    4.9
    Medium

    CVE-2013-7266

    Last Modified: 11 Apr 2025

    The mISDN_sock_recvmsg function in drivers/isdn/mISDN/socket.c in the Linux kernel before 3.12.4 does not ensure that a certain length value is consistent with the size of an associated data structure, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.

    Published: 21 Nov 2013
    3.3
    Low

    CVE-2012-6607

    Last Modified: 11 Apr 2025

    The transform_save function in transform.c in Augeas before 1.0.0 allows local users to overwrite arbitrary files and obtain sensitive information via a symlink attack on a .augsave file in a backup save action, a different vector than CVE-2012-0786.

    Published: 21 Nov 2013
    2.1
    Low

    CVE-2013-6372

    Last Modified: 12 Apr 2025

    The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.

    Published: 21 Nov 2013
    4.9
    Medium

    CVE-2013-7268

    Last Modified: 11 Apr 2025

    The ipx_recvmsg function in net/ipx/af_ipx.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.

    Published: 21 Nov 2013
    4.9
    Medium

    CVE-2013-7269

    Last Modified: 11 Apr 2025

    The nr_recvmsg function in net/netrom/af_netrom.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.

    Published: 21 Nov 2013
    4.9
    Medium

    CVE-2013-7270

    Last Modified: 11 Apr 2025

    The packet_recvmsg function in net/packet/af_packet.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.

    Published: 21 Nov 2013
    4.9
    Medium

    CVE-2013-7271

    Last Modified: 11 Apr 2025

    The x25_recvmsg function in net/x25/af_x25.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.

    Published: 21 Nov 2013
    3.5
    Low

    CVE-2013-6374

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Nov 2013
    4.7
    Medium

    CVE-2013-7026

    Last Modified: 11 Apr 2025

    Multiple race conditions in ipc/shm.c in the Linux kernel before 3.12.2 allow local users to cause a denial of service (use-after-free and system crash) or possibly have unspecified other impact via a crafted application that uses shmctl IPC_RMID operations in conjunction with other shm system calls.

    Published: 21 Nov 2013
    4.9
    Medium

    CVE-2013-7267

    Last Modified: 11 Apr 2025

    The atalk_recvmsg function in net/appletalk/ddp.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.

    Published: 21 Nov 2013
    5
    Medium

    CVE-2013-6827

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in admin/viewmsg.php in PineApp Mail-SeCure allows remote attackers to read arbitrary files via a full pathname in the msg parameter.

    Published: 20 Nov 2013
    7.5
    High

    CVE-2013-6829

    Last Modified: 11 Apr 2025

    admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation.

    Published: 20 Nov 2013
    7.2
    High

    CVE-2013-6831

    Last Modified: 11 Apr 2025

    PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo command that leverages access to the qmailq account.

    Published: 20 Nov 2013