CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2013-6820

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in the SAP NetWeaver Development Infrastructure (NWDI) allows remote attackers to execute arbitrary code by uploading a file with an executable extension via unspecified vectors.

    Published: 19 Nov 2013
    5
    Medium

    CVE-2013-6821

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Exportability Check Service in SAP NetWeaver allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 19 Nov 2013
    6.4
    Medium

    CVE-2013-6823

    Last Modified: 11 Apr 2025

    GRMGApp in SAP NetWeaver allows remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 19 Nov 2013
    6.8
    Medium

    CVE-2013-6826

    Last Modified: 11 Apr 2025

    cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.

    Published: 19 Nov 2013
    6.8
    Medium

    CVE-2013-6817

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in SAP Network Interface Router (SAProuter) 7.30 allows remote attackers to cause a denial of service and execute arbitrary code via crafted NI Route messages.

    Published: 19 Nov 2013
    10
    Critical

    CVE-2013-6822

    Last Modified: 11 Apr 2025

    GRMGApp in SAP NetWeaver allows remote attackers to have unspecified impact and attack vectors, related to an XML External Entity (XXE) issue.

    Published: 19 Nov 2013
    8.8
    High

    CVE-2013-6282

    Last Modified: 22 Apr 2026

    The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

    Published: 19 Nov 2013
    4.3
    Medium

    CVE-2013-4507

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in CollectiveAccess Providence and Pawtucket before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Nov 2013
    4.3
    Medium

    CVE-2013-5215

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web interface "WiFi scan" option in FOSCAM Wireless IP Cameras allows remote attackers to inject arbitrary web script or HTML via the SSID.

    Published: 19 Nov 2013
    6.8
    Medium

    CVE-2013-5730

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DSL-2740B Gateway with firmware EU_1.00 allow remote attackers to hijack the authentication of administrators for requests that (1) enable or disable Wireless MAC Address Filters via a wlFltMode action to wlmacflt.cmd, (2) enable or disable firewall protections via a request to scdmz.cmd, or (3) enable or disable remote management via a save action to scsrvcntr.cmd.

    Published: 19 Nov 2013
    4.3
    Medium

    CVE-2013-5966

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ZK Framework before 5.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Nov 2013
    4.3
    Medium

    CVE-2013-6074

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite 7.2.x before 7.2.2-rev25 and 7.4.x before 7.4.0-rev14 allows remote attackers to inject arbitrary web script or HTML via an attached SVG file.

    Published: 19 Nov 2013
    6.8
    Medium

    CVE-2013-3095

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password or (2) enable remote management via a request to hedwig.cgi or (3) activate configuration changes via a request to pigwidgeon.cgi.

    Published: 19 Nov 2013
    7.5
    High

    CVE-2013-5607

    Last Modified: 25 Nov 2025

    Integer overflow in the PL_ArenaAllocate function in Mozilla Netscape Portable Runtime (NSPR) before 4.10.2, as used in Firefox before 25.0.1, Firefox ESR 17.x before 17.0.11 and 24.x before 24.1.1, and SeaMonkey before 2.22.1, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted X.509 certificate, a related issue to CVE-2013-1741.

    Published: 19 Nov 2013
    4.6
    Medium

    CVE-2013-7348

    Last Modified: 12 Apr 2025

    Double free vulnerability in the ioctx_alloc function in fs/aio.c in the Linux kernel before 3.12.4 allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via vectors involving an error condition in the aio_setup_ring function.

    Published: 19 Nov 2013
    5
    Medium

    CVE-2013-4564

    Last Modified: 11 Apr 2025

    Libreswan 3.6 allows remote attackers to cause a denial of service (crash) via a small length value and (1) no version or (2) an invalid major number in an IKE packet.

    Published: 18 Nov 2013
    4.9
    Medium

    CVE-2013-7281

    Last Modified: 11 Apr 2025

    The dgram_recvmsg function in net/ieee802154/dgram.c in the Linux kernel before 3.12.4 updates a certain length value without ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.

    Published: 18 Nov 2013
    4.6
    Medium

    CVE-2013-6432

    Last Modified: 11 Apr 2025

    The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging unspecified privileges to execute a crafted application.

    Published: 18 Nov 2013
    4.9
    Medium

    CVE-2013-7264

    Last Modified: 11 Apr 2025

    The l2tp_ip_recvmsg function in net/l2tp/l2tp_ip.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.

    Published: 18 Nov 2013
    4.9
    Medium

    CVE-2013-7265

    Last Modified: 11 Apr 2025

    The pn_recvmsg function in net/phonet/datagram.c in the Linux kernel before 3.12.4 updates a certain length value before ensuring that an associated data structure has been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call.

    Published: 18 Nov 2013
    4.9
    Medium

    CVE-2013-7263

    Last Modified: 11 Apr 2025

    The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call, related to net/ipv4/ping.c, net/ipv4/raw.c, net/ipv4/udp.c, net/ipv6/raw.c, and net/ipv6/udp.c.

    Published: 18 Nov 2013
    4.3
    Medium

    CVE-2013-4006

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.5.1 uses weak permissions for unspecified files, which allows local users to obtain sensitive information via standard filesystem operations.

    Published: 16 Nov 2013
    5.8
    Medium

    CVE-2013-6802

    Last Modified: 11 Apr 2025

    Google Chrome before 31.0.1650.57 allows remote attackers to bypass intended sandbox restrictions by leveraging access to a renderer process, as demonstrated during a Mobile Pwn2Own competition at PacSec 2013, a different vulnerability than CVE-2013-6632.

    Published: 16 Nov 2013
    3.5
    Low

    CVE-2013-5414

    Last Modified: 11 Apr 2025

    The migration functionality in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 does not properly support the distinction between the admin role and the adminsecmanager role, which allows remote authenticated users to gain privileges in opportunistic circumstances by accessing resources in between a migration and a role evaluation.

    Published: 16 Nov 2013
    4.3
    Medium

    CVE-2013-5417

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote attackers to inject arbitrary web script or HTML via HTTP response data.

    Published: 16 Nov 2013
    3.5
    Low

    CVE-2013-5418

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 16 Nov 2013
    5.8
    Medium

    CVE-2013-5606

    Last Modified: 11 Apr 2025

    The CERT_VerifyCert function in lib/certhigh/certvfy.c in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 provides an unexpected return value for an incompatible key-usage certificate when the CERTVerifyLog argument is valid, which might allow remote attackers to bypass intended access restrictions via a crafted certificate.

    Published: 16 Nov 2013
    7.2
    High

    CVE-2013-5972

    Last Modified: 11 Apr 2025

    VMware Workstation 9.x before 9.0.3 and VMware Player 5.x before 5.0.3 on Linux do not properly handle shared libraries, which allows host OS users to gain host OS privileges via unspecified vectors.

    Published: 16 Nov 2013
    9.3
    Critical

    CVE-2013-6632

    Last Modified: 11 Apr 2025

    Integer overflow in Google Chrome before 31.0.1650.57 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, as demonstrated during a Mobile Pwn2Own competition at PacSec 2013.

    Published: 16 Nov 2013
    7.5
    High

    CVE-2013-1741

    Last Modified: 11 Apr 2025

    Integer overflow in Mozilla Network Security Services (NSS) 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large size value.

    Published: 16 Nov 2013
    7.1
    High

    CVE-2013-6801

    Last Modified: 11 Apr 2025

    Microsoft Word 2003 SP2 and SP3 on Windows XP SP3 allows remote attackers to cause a denial of service (CPU consumption) via a malformed .doc file containing an embedded image, as demonstrated by word2003forkbomb.doc, related to a "fork bomb" issue.

    Published: 16 Nov 2013
    4.7
    Medium

    CVE-2013-6799

    Last Modified: 11 Apr 2025

    Apple Mac OS X 10.9 allows local users to cause a denial of service (memory corruption or panic) by creating a hard link to a directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-0105.

    Published: 16 Nov 2013
    4.7
    Medium

    CVE-2013-5193

    Last Modified: 11 Apr 2025

    The App Store component in Apple iOS before 7.0.4 does not properly enforce an intended transaction-time password requirement, which allows local users to complete a (1) App purchase or (2) In-App purchase by leveraging previous entry of Apple ID credentials.

    Published: 16 Nov 2013
    5.8
    Medium

    CVE-2013-6798

    Last Modified: 11 Apr 2025

    BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not properly determine the user account for execution of Peer Manager in certain situations involving successive logins with different accounts, which allows context-dependent attackers to bypass intended restrictions on remote file-access folders via IPv6 WebDAV requests, a different vulnerability than CVE-2013-3694.

    Published: 16 Nov 2013
    4
    Medium

    CVE-2013-4034

    Last Modified: 11 Apr 2025

    IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 16 Nov 2013
    4.3
    Medium

    CVE-2013-4842

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Integrated Lights-Out 4 (iLO4) with firmware before 1.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Nov 2013
    6.3
    Medium

    CVE-2013-6688

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the license-upload interface in the Enterprise License Manager (ELM) component in Cisco Unified Communications Manager 9.1(1) and earlier allows remote authenticated users to create arbitrary files via a crafted path, aka Bug ID CSCui58222.

    Published: 16 Nov 2013
    6.8
    Medium

    CVE-2013-3406

    Last Modified: 11 Apr 2025

    The "Files Available for Download" implementation in the Cisco Intelligent Automation for Cloud component in Cisco Services Portal 9.4(1) allows remote authenticated users to read arbitrary files via a crafted request, aka Bug ID CSCug65687.

    Published: 16 Nov 2013
    5
    Medium

    CVE-2013-3407

    Last Modified: 11 Apr 2025

    The web interface in Cisco Server Provisioner 6.4.0 Patch 5-1301292331 and earlier does not require authentication for unspecified pages, which allows remote attackers to obtain sensitive information via a direct request, aka Bug ID CSCug65664.

    Published: 16 Nov 2013
    6.8
    Medium

    CVE-2013-3694

    Last Modified: 11 Apr 2025

    BlackBerry Link before 1.2.1.31 on Windows and before 1.1.1 build 39 on Mac OS X does not require authentication for remote file-access folders, which allows remote attackers to read or create arbitrary files via IPv6 WebDAV requests, as demonstrated by a CSRF attack involving DNS rebinding.

    Published: 16 Nov 2013
    3.5
    Low

    CVE-2013-5425

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administration Console in IBM WebSphere Virtual Enterprise 6.1 before 6.1.1.6 and 7.0 before 7.0.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 16 Nov 2013
    4.3
    Medium

    CVE-2013-5454

    Last Modified: 11 Apr 2025

    IBM WebSphere Portal 6.0 through 6.0.1.7, 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF25, and 8.0 through 8.0.0.1 CF08 allows remote attackers to read arbitrary files via a modified URL.

    Published: 16 Nov 2013
    6.8
    Medium

    CVE-2013-6686

    Last Modified: 11 Apr 2025

    The SSL VPN implementation in Cisco IOS 15.3(1)T2 and earlier allows remote authenticated users to cause a denial of service (interface queue wedge) via crafted DTLS packets in an SSL session, aka Bug IDs CSCuh97409 and CSCud90568.

    Published: 16 Nov 2013
    5
    Medium

    CVE-2013-3030

    Last Modified: 11 Apr 2025

    The servlet gateway in IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote attackers to cause a denial of service (temporary gateway outage) via crafted HTTP requests.

    Published: 16 Nov 2013
    7.1
    High

    CVE-2013-3876

    Last Modified: 11 Apr 2025

    DirectAccess in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly verify server X.509 certificates, which allows man-in-the-middle attackers to spoof servers and read encrypted domain credentials via a crafted certificate.

    Published: 16 Nov 2013
    6.8
    Medium

    CVE-2013-4843

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Integrated Lights-Out 4 (iLO4) with firmware before 1.32 allows remote authenticated users to obtain sensitive information via unknown vectors.

    Published: 16 Nov 2013
    6.8
    Medium

    CVE-2013-5556

    Last Modified: 11 Apr 2025

    The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340.

    Published: 16 Nov 2013
    6.9
    Medium

    CVE-2013-6689

    Last Modified: 11 Apr 2025

    Cisco Unified Communications Manager (Unified CM) 9.1(1) and earlier allows local users to bypass file permissions, and read, modify, or create arbitrary files, via an "overload" of the command-line utility, aka Bug ID CSCui58229.

    Published: 16 Nov 2013
    5.4
    Medium

    CVE-2013-5223

    Last Modified: 22 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add action or (12) rmLst parameter in a remove action to prmngr.cmd, (13) ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15) smbDirName parameter to samba.cgi, or (16) wlSsid parameter to wlcfg.wl.

    Published: 15 Nov 2013
    7.6
    High

    CVE-2013-2271

    Last Modified: 11 Apr 2025

    The D-Link DSL-2740B Gateway with firmware EU_1.0, when an active administrator session exists, allows remote attackers to bypass authentication and gain administrator access via a request to login.cgi.

    Published: 15 Nov 2013