CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-6623

    Last Modified: 11 Apr 2025

    The SVG implementation in Blink, as used in Google Chrome before 31.0.1650.48, allows remote attackers to cause a denial of service (out-of-bounds read) by leveraging the use of tree order, rather than transitive dependency order, for layout.

    Published: 13 Nov 2013
    7.5
    High

    CVE-2013-6624

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving the string values of id attributes.

    Published: 13 Nov 2013
    4.3
    Medium

    CVE-2013-6628

    Last Modified: 11 Apr 2025

    net/socket/ssl_client_socket_nss.cc in the TLS implementation in Google Chrome before 31.0.1650.48 does not ensure that a server's X.509 certificate is the same during renegotiation as it was before renegotiation, which might allow remote web servers to interfere with trust relationships by renegotiating a session.

    Published: 13 Nov 2013
    3.5
    Low

    CVE-2013-5326

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Adobe ColdFusion 9.0 before Update 12, 9.0.1 before Update 11, 9.0.2 before Update 6, and 10 before Update 12, when the CFIDE directory is available, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to the logviewer directory.

    Published: 13 Nov 2013
    7.8
    High

    CVE-2013-5328

    Last Modified: 11 Apr 2025

    Adobe ColdFusion 10 before Update 12 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-1324

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "Word Stack Buffer Overwrite Vulnerability."

    Published: 13 Nov 2013
    5
    Medium

    CVE-2013-3869

    Last Modified: 11 Apr 2025

    Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to cause a denial of service (daemon hang) via a web-service request containing a crafted X.509 certificate that is not properly handled during validation, aka "Digital Signatures Vulnerability."

    Published: 13 Nov 2013
    4.9
    Medium

    CVE-2013-3887

    Last Modified: 11 Apr 2025

    The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows local users to obtain sensitive information from kernel memory by leveraging improper copy operations, aka "Ancillary Function Driver Information Disclosure Vulnerability."

    Published: 13 Nov 2013
    7.9
    High

    CVE-2013-3898

    Last Modified: 11 Apr 2025

    Microsoft Windows 8 and Windows Server 2012, when Hyper-V is used, does not ensure memory-address validity, which allows guest OS users to execute arbitrary code in all guest OS instances, and allows guest OS users to cause a denial of service (host OS crash), via a guest-to-host hypercall with a crafted function parameter, aka "Address Corruption Vulnerability."

    Published: 13 Nov 2013
    5
    Medium

    CVE-2013-3905

    Last Modified: 11 Apr 2025

    Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."

    Published: 13 Nov 2013
    4.3
    Medium

    CVE-2013-3908

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information from any visited document via a crafted web page that is not properly handled during a print-preview action, aka "Internet Explorer Information Disclosure Vulnerability."

    Published: 13 Nov 2013
    4.3
    Medium

    CVE-2013-3909

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 8 allows remote attackers to read content from a different (1) domain or (2) zone via crafted characters in Cascading Style Sheets (CSS) token sequences, aka "Internet Explorer Information Disclosure Vulnerability."

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-3910

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-3911

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-3912

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3916.

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-3914

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-3915

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3917.

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-3916

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3912.

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-3917

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3915.

    Published: 13 Nov 2013
    5.5
    Medium

    CVE-2013-4423

    Last Modified: 21 Nov 2024

    CloudForms stores user passwords in recoverable format

    Published: 13 Nov 2013
    5
    Medium

    CVE-2013-6789

    Last Modified: 11 Apr 2025

    security/MemberLoginForm.php in SilverStripe 3.0.3 supports credentials in a GET request, which allows remote or local attackers to obtain sensitive information by reading web-server access logs, web-server Referer logs, or the browser history, a similar vulnerability to CVE-2013-2653.

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-0082

    Last Modified: 11 Apr 2025

    Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "WPD File Format Memory Corruption Vulnerability."

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-1325

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "Word Heap Overwrite Vulnerability."

    Published: 13 Nov 2013
    7.5
    High

    CVE-2013-2049

    Last Modified: 21 Nov 2024

    Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.

    Published: 13 Nov 2013
    5.8
    Medium

    CVE-2013-2653

    Last Modified: 11 Apr 2025

    security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing attacks without detection by the victim.

    Published: 13 Nov 2013
    8.8
    High

    CVE-2013-0185

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

    Published: 13 Nov 2013
    7.5
    High

    CVE-2013-2050

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise Virtualization Manager 5.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the profile[] parameter in an explorer action.

    Published: 13 Nov 2013
    9.3
    Critical

    CVE-2013-3940

    Last Modified: 11 Apr 2025

    Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image in a Windows Write (.wri) document, which is not properly handled in WordPad, aka "Graphics Device Interface Integer Overflow Vulnerability."

    Published: 13 Nov 2013
    7.5
    High

    CVE-2013-5605

    Last Modified: 11 Apr 2025

    Mozilla Network Security Services (NSS) 3.14 before 3.14.5 and 3.15 before 3.15.3 allows remote attackers to cause a denial of service or possibly have unspecified other impact via invalid handshake packets.

    Published: 13 Nov 2013
    6.8
    Medium

    CVE-2013-5726

    Last Modified: 11 Apr 2025

    Tweetbot 1.3.3 for Mac, and 2.8.5 for iPad and iPhone, does not require confirmation of (1) follow or (2) favorite actions, which allows remote attackers to automatically force the user to perform undesired actions, as demonstrated via the tweetbot:///follow/ URL.

    Published: 12 Nov 2013
    8.8
    High

    CVE-2013-3918

    Last Modified: 22 Apr 2026

    The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."

    Published: 12 Nov 2013
    4.7
    Medium

    CVE-2013-4512

    Last Modified: 11 Apr 2025

    Buffer overflow in the exitcode_proc_write function in arch/um/kernel/exitcode.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact by leveraging root privileges for a write operation.

    Published: 12 Nov 2013
    4.9
    Medium

    CVE-2013-4513

    Last Modified: 11 Apr 2025

    Buffer overflow in the oz_cdev_write function in drivers/staging/ozwpan/ozcdev.c in the Linux kernel before 3.12 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted write operation.

    Published: 12 Nov 2013
    4.7
    Medium

    CVE-2013-4514

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in drivers/staging/wlags49_h2/wl_priv.c in the Linux kernel before 3.12 allow local users to cause a denial of service or possibly have unspecified other impact by leveraging the CAP_NET_ADMIN capability and providing a long station-name string, related to the (1) wvlan_uil_put_info and (2) wvlan_set_station_nickname functions.

    Published: 12 Nov 2013
    4.9
    Medium

    CVE-2013-4515

    Last Modified: 11 Apr 2025

    The bcm_char_ioctl function in drivers/staging/bcm/Bcmchar.c in the Linux kernel before 3.12 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via an IOCTL_BCM_GET_DEVICE_DRIVER_INFO ioctl call.

    Published: 12 Nov 2013
    4.9
    Medium

    CVE-2013-4516

    Last Modified: 11 Apr 2025

    The mp_get_count function in drivers/staging/sb105x/sb_pci_mp.c in the Linux kernel before 3.12 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a TIOCGICOUNT ioctl call.

    Published: 12 Nov 2013
    4.7
    Medium

    CVE-2013-2239

    Last Modified: 11 Apr 2025

    vzkernel before 042stab080.2 in the OpenVZ modification for the Linux kernel 2.6.32 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via (1) a crafted ploop driver ioctl call, related to the ploop_getdevice_ioc function in drivers/block/ploop/dev.c, or (2) a crafted quotactl system call, related to the compat_quotactl function in fs/quota/quota.c.

    Published: 12 Nov 2013
    6.9
    Medium

    CVE-2013-4740

    Last Modified: 11 Apr 2025

    goodix_tool.c in the Goodix gt915 touchscreen driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, relies on user-space length values for kernel-memory copies of procfs file content, which allows attackers to gain privileges or cause a denial of service (memory corruption) via an application that provides crafted values.

    Published: 12 Nov 2013
    6.9
    Medium

    CVE-2013-6763

    Last Modified: 11 Apr 2025

    The uio_mmap_physical function in drivers/uio/uio.c in the Linux kernel before 3.12 does not validate the size of a memory block, which allows local users to cause a denial of service (memory corruption) or possibly gain privileges via crafted mmap operations, a different vulnerability than CVE-2013-4511.

    Published: 12 Nov 2013
    6.9
    Medium

    CVE-2013-4511

    Last Modified: 11 Apr 2025

    Multiple integer overflows in Alchemy LCD frame-buffer drivers in the Linux kernel before 3.12 allow local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted mmap operations, related to the (1) au1100fb_fb_mmap function in drivers/video/au1100fb.c and the (2) au1200fb_fb_mmap function in drivers/video/au1200fb.c.

    Published: 12 Nov 2013
    6.9
    Medium

    CVE-2013-6122

    Last Modified: 11 Apr 2025

    goodix_tool.c in the Goodix gt915 touchscreen driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly synchronize updates to a global variable, which allows local users to bypass intended access restrictions or cause a denial of service (memory corruption) via crafted arguments to the procfs write handler.

    Published: 12 Nov 2013
    5
    Medium

    CVE-2013-6629

    Last Modified: 25 Nov 2025

    The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

    Published: 12 Nov 2013
    7.5
    High

    CVE-2013-4480

    Last Modified: 11 Apr 2025

    Red Hat Satellite 5.6 and earlier does not disable the web interface that is used to create the first user for a satellite, which allows remote attackers to create administrator accounts.

    Published: 12 Nov 2013
    5
    Medium

    CVE-2013-6630

    Last Modified: 11 Apr 2025

    The get_dht function in jdmarker.c in libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48 and other products, does not set all elements of a certain Huffman value array during the reading of segments that follow Define Huffman Table (DHT) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.

    Published: 12 Nov 2013
    10
    Critical

    CVE-2013-5329

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5330.

    Published: 12 Nov 2013
    10
    Critical

    CVE-2013-5330

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 11.7.700.252 and 11.8.x and 11.9.x before 11.9.900.152 on Windows and Mac OS X and before 11.2.202.327 on Linux, Adobe AIR before 3.9.0.1210, Adobe AIR SDK before 3.9.0.1210, and Adobe AIR SDK & Compiler before 3.9.0.1210 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-5329.

    Published: 12 Nov 2013
    1.2
    Low

    CVE-2013-4476

    Last Modified: 11 Apr 2025

    Samba 4.0.x before 4.0.11 and 4.1.x before 4.1.1, when LDAP or HTTP is provided over SSL, uses world-readable permissions for a private key, which allows local users to obtain sensitive information by reading the key file, as demonstrated by access to the local filesystem on an AD domain controller.

    Published: 11 Nov 2013
    7
    High

    CVE-2013-4588

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability for (1) a getsockopt system call, related to the do_ip_vs_get_ctl function, or (2) a setsockopt system call, related to the do_ip_vs_set_ctl function.

    Published: 11 Nov 2013
    4.3
    Medium

    CVE-2013-6780

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in uploader.swf in the Uploader component in Yahoo! YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via the allowedDomain parameter.

    Published: 11 Nov 2013
    2.9
    Low

    CVE-2013-3985

    Last Modified: 11 Apr 2025

    The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 does not properly restrict application cookies, which allows remote attackers to read session variables by leveraging a weak setting of the Domain variable.

    Published: 9 Nov 2013