CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2013-0537

    Last Modified: 11 Apr 2025

    The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of shared links by leveraging meeting-attendance privileges.

    Published: 9 Nov 2013
    3.5
    Low

    CVE-2013-3044

    Last Modified: 11 Apr 2025

    The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to spoof the origin of chat messages, or compose anonymous chat messages, by leveraging meeting-attendance privileges.

    Published: 9 Nov 2013
    3.5
    Low

    CVE-2013-3045

    Last Modified: 11 Apr 2025

    The Enterprise Meeting Server in IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote authenticated users to share crafted links via the Library function.

    Published: 9 Nov 2013
    4.9
    Medium

    CVE-2014-8172

    Last Modified: 12 Apr 2025

    The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or system crash) via unspecified use of Asynchronous I/O (AIO) operations.

    Published: 9 Nov 2013
    4.3
    Medium

    CVE-2013-3986

    Last Modified: 11 Apr 2025

    IBM Lotus Sametime 8.5.2 and 8.5.2.1 allows remote attackers to cause a denial of service (WebPlayer Firefox extension crash) via a crafted Audio Visual (AV) session.

    Published: 8 Nov 2013
    6
    Medium

    CVE-2013-4050

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

    Published: 8 Nov 2013
    3.5
    Low

    CVE-2013-4051

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-4055.

    Published: 8 Nov 2013
    3.5
    Low

    CVE-2013-4055

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in webadmin.nsf in Domino Web Administrator in IBM Domino 8.5 and 9.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-4051.

    Published: 8 Nov 2013
    7.5
    High

    CVE-2013-4508

    Last Modified: 11 Apr 2025

    lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.

    Published: 8 Nov 2013
    7.5
    High

    CVE-2013-5554

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the web-management interface in the server in Cisco Wide Area Application Services (WAAS) Mobile before 3.5.5 allows remote attackers to upload and execute arbitrary files via a crafted POST request, aka Bug ID CSCuh69773.

    Published: 8 Nov 2013
    4.3
    Medium

    CVE-2013-4716

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Tattyan HP TOWN 5_9_3 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.

    Published: 8 Nov 2013
    7.8
    High

    CVE-2013-5553

    Last Modified: 11 Apr 2025

    Multiple memory leaks in Cisco IOS 15.1 before 15.1(4)M7 allow remote attackers to cause a denial of service (memory consumption or device reload) by sending a crafted SIP message over (1) IPv4 or (2) IPv6, aka Bug IDs CSCuc42558 and CSCug25383.

    Published: 8 Nov 2013
    4.3
    Medium

    CVE-2013-5565

    Last Modified: 11 Apr 2025

    The OSPFv3 functionality in Cisco IOS XR 5.1 allows remote attackers to cause a denial of service (process crash) via a malformed LSA Type-1 packet, aka Bug ID CSCuj82176.

    Published: 8 Nov 2013
    5
    Medium

    CVE-2013-5566

    Last Modified: 11 Apr 2025

    Cisco NX-OS 5.0 and earlier on MDS 9000 devices allows remote attackers to cause a denial of service (supervisor CPU consumption) via Authentication Header (AH) authentication in a Virtual Router Redundancy Protocol (VRRP) frame, aka Bug ID CSCte27874.

    Published: 8 Nov 2013
    8.5
    High

    CVE-2013-4987

    Last Modified: 11 Apr 2025

    PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters in a "system ping" command.

    Published: 8 Nov 2013
    10
    Critical

    CVE-2013-5558

    Last Modified: 11 Apr 2025

    The WIL-A module in Cisco TelePresence VX Clinical Assistant 1.2 before 1.21 changes the admin password to an empty password upon a reboot, which makes it easier for remote attackers to obtain access via the administrative interface, aka Bug ID CSCuj17238.

    Published: 8 Nov 2013
    5.7
    Medium

    CVE-2013-4551

    Last Modified: 11 Apr 2025

    Xen 4.2.x and 4.3.x, when nested virtualization is disabled, does not properly check the emulation paths for (1) VMLAUNCH and (2) VMRESUME, which allows local HVM guest users to cause a denial of service (host crash) via unspecified vectors related to "guest VMX instruction execution."

    Published: 8 Nov 2013
    9.3
    Critical

    CVE-2013-7283

    Last Modified: 11 Apr 2025

    Race condition in the libreswan.spec files for Red Hat Enterprise Linux (RHEL) and Fedora packages in libreswan 3.6 has unspecified impact and attack vectors, involving the /var/tmp/libreswan-nss-pwd temporary file.

    Published: 8 Nov 2013
    3.3
    Low

    CVE-2013-2929

    Last Modified: 11 Apr 2025

    The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c and arch/ia64/include/asm/processor.h.

    Published: 7 Nov 2013
    6
    Medium

    CVE-2013-4548

    Last Modified: 11 Apr 2025

    The mm_newkeys_from_blob function in monitor_wrap.c in sshd in OpenSSH 6.2 and 6.3, when an AES-GCM cipher is used, does not properly initialize memory for a MAC context data structure, which allows remote authenticated users to bypass intended ForceCommand and login-shell restrictions via packet data that provides a crafted callback address.

    Published: 7 Nov 2013
    7.8
    High

    CVE-2013-3906

    Last Modified: 22 Apr 2026

    GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and exploited in the wild in October and November 2013.

    Published: 6 Nov 2013
    4.3
    Medium

    CVE-2013-3281

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in EMC Documentum Webtop before 6.7 SP2 P07, Documentum WDK before 6.7 SP2 P07, Documentum Taskspace before 6.7 SP2 P07, Documentum Records Manager before 6.7 SP2 P07, Documentum Web Publisher before 6.5 SP7, Documentum Digital Asset Manager before 6.5 SP6, Documentum Administrator before 6.7 SP2 P07, and Documentum Capital Projects before 1.8 P01 allows remote attackers to inject arbitrary web script or HTML via a crafted parameter in a URL.

    Published: 6 Nov 2013
    9.3
    Critical

    CVE-2013-3626

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Session Server in Attachmate Verastream Host Integrator (VHI) 6.0 through 7.5 SP 1 HF 1 allows remote attackers to upload and execute arbitrary files via a crafted message.

    Published: 6 Nov 2013
    5
    Medium

    CVE-2013-5562

    Last Modified: 11 Apr 2025

    The ITM web server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (temporary HTTP service outage) via a flood of TCP packets, aka Bug ID CSCuh36313.

    Published: 6 Nov 2013
    4.3
    Medium

    CVE-2013-3286

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom before 7.4.4 P11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 6 Nov 2013
    4.3
    Medium

    CVE-2013-4714

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Nov 2013
    7.5
    High

    CVE-2013-4715

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 6 Nov 2013
    4.3
    Medium

    CVE-2013-5387

    Last Modified: 11 Apr 2025

    Buffer overflow in IBM Platform Symphony 5.2, 6.1, and 6.1.1 allows remote attackers to cause a denial of service (process crash or hang) via a malformed SOAP request with a large amount of request data.

    Published: 6 Nov 2013
    4.3
    Medium

    CVE-2013-5563

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Query/NewQueryResult.jsp in Cisco Security Monitoring, Analysis and Response System (CS-MARS) allows remote attackers to inject arbitrary web script or HTML via the isnowLatency parameter, aka Bug ID CSCul16173.

    Published: 6 Nov 2013
    6.8
    Medium

    CVE-2013-6230

    Last Modified: 11 Apr 2025

    The Winsock WSAIoctl API in Microsoft Windows Server 2008, as used in ISC BIND 9.6-ESV before 9.6-ESV-R10-P1, 9.8 before 9.8.6-P1, 9.9 before 9.9.4-P1, 9.9.3-S1, 9.9.4-S1, and other products, does not properly support the SIO_GET_INTERFACE_LIST command for netmask 255.255.255.255, which allows remote attackers to bypass intended IP address restrictions by leveraging misinterpretation of this netmask as a 0.0.0.0 netmask.

    Published: 6 Nov 2013
    4.3
    Medium

    CVE-2013-4135

    Last Modified: 11 Apr 2025

    The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 5 Nov 2013
    5.5
    Medium

    CVE-2013-5688

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2) get_content action, or (3) upload arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the dir parameter in an upload action.

    Published: 5 Nov 2013
    Unknown

    CVE-2013-5689

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5688. Reason: This issue has been MERGED with CVE-2013-5688 in accordance with CVE content decisions, because it is the same type of vulnerability affecting the same versions. Notes: All CVE users should reference CVE-2013-5688 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Nov 2013
    4.3
    Medium

    CVE-2013-4134

    Last Modified: 11 Apr 2025

    OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which makes it easier for remote attackers to obtain the service key.

    Published: 5 Nov 2013
    4.3
    Medium

    CVE-2013-3263

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl parameter to campaign/campaignone.php; the (2) action, (3) campaignname, (4) campaignformat, or (5) emailtemplate parameter to campaign/campaigntwo.php; the (6) listid parameter to list/edit.php; the (7) campaignid or (8) siteurl parameter to campaign/editcampaign.php; the (9) campaignid parameter to campaign/selectlistb4send.php; the (10) campaignid, (11) campaignname, (12) campaignsubject, or (13) selectedcampaigns parameter to campaign/sendCampaign.php; or the (14) campaignid, (15) campaignname, (16) campaignformat, or (17) action parameter to campaign/updatecampaign.php.

    Published: 5 Nov 2013
    4.3
    Medium

    CVE-2013-4453

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in templates/login.php in LDAP Account Manager (LAM) 4.3 and 4.2.1 allows remote attackers to inject arbitrary web script or HTML via the language parameter.

    Published: 5 Nov 2013
    7.5
    High

    CVE-2013-5694

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands via the service_selection parameter.

    Published: 5 Nov 2013
    4.3
    Medium

    CVE-2013-5695

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Opsview before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to admin/auditlog/, (2) PATH_INFO to info/host/ or (3) viewport/, (4) back parameter to login, or (5) "from" parameter to status/service/recheck.

    Published: 5 Nov 2013
    9
    Critical

    CVE-2013-6618

    Last Modified: 11 Apr 2025

    jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to execute arbitrary commands via the rsargs parameter in an exec action.

    Published: 5 Nov 2013
    6.4
    Medium

    CVE-2013-3264

    Last Modified: 11 Apr 2025

    The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2) campaign/editCampaign.php, which allows remote attackers to modify list or campaign data.

    Published: 5 Nov 2013
    6
    Medium

    CVE-2013-4435

    Last Modified: 11 Apr 2025

    Salt (aka SaltStack) 0.15.0 through 0.17.0 allows remote authenticated users who are using external authentication or client ACL to execute restricted routines by embedding the routine in another routine.

    Published: 5 Nov 2013
    9.3
    Critical

    CVE-2013-4436

    Last Modified: 11 Apr 2025

    The default configuration for salt-ssh in Salt (aka SaltStack) 0.17.0 does not validate the SSH host key of requests, which allows remote attackers to have unspecified impact via a man-in-the-middle (MITM) attack.

    Published: 5 Nov 2013
    10
    Critical

    CVE-2013-4437

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp."

    Published: 5 Nov 2013
    7.5
    High

    CVE-2013-4438

    Last Modified: 11 Apr 2025

    Salt (aka SaltStack) before 0.17.1 allows remote attackers to execute arbitrary YAML code via unspecified vectors. NOTE: the vendor states that this might not be a vulnerability because the YAML to be loaded has already been determined to be safe.

    Published: 5 Nov 2013
    4.9
    Medium

    CVE-2013-4439

    Last Modified: 11 Apr 2025

    Salt (aka SaltStack) before 0.15.0 through 0.17.0 allows remote authenticated minions to impersonate arbitrary minions via a crafted minion with a valid key.

    Published: 5 Nov 2013
    4.3
    Medium

    CVE-2011-5267

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as used in WikiWig 5.01 and possibly other products, allow remote attackers to inject arbitrary web script or HTML via the (1) to_p_dict or (2) to_r_list parameter. NOTE: this issue might be related to the htmlarea plugin and CVE-2013-5670.

    Published: 5 Nov 2013
    4.3
    Medium

    CVE-2013-5670

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in spell-check-savedicts.php in the htmlarea SpellChecker module, as used in Serendipity before 1.7.3 and possibly other products, allows remote attackers to inject arbitrary web script or HTML via the to_r_list parameter.

    Published: 5 Nov 2013
    5.8
    Medium

    CVE-2013-6077

    Last Modified: 11 Apr 2025

    Citrix XenDesktop 7.0, when upgraded from XenDesktop 5.x, does not properly enforce policy rule permissions, which allows remote attackers to bypass intended restrictions.

    Published: 5 Nov 2013
    10
    Critical

    CVE-2013-6617

    Last Modified: 11 Apr 2025

    The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.

    Published: 5 Nov 2013
    7.5
    High

    CVE-2013-6172

    Last Modified: 11 Apr 2025

    steps/utils/save_pref.inc in Roundcube webmail before 0.8.7 and 0.9.x before 0.9.5 allows remote attackers to modify configuration settings via the _session parameter, which can be leveraged to read arbitrary files, conduct SQL injection attacks, and execute arbitrary code.

    Published: 5 Nov 2013