CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2013-4041

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Java SDK 5.0.0 before SR16 FP4, 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to access restricted classes via unspecified vectors.

    Published: 5 Nov 2013
    6.8
    Medium

    CVE-2013-5375

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, 6.0.0 before SR15, and 5.0.0 before SR16 FP4 allows remote attackers to access restricted classes via unspecified vectors related to XML and XSL.

    Published: 5 Nov 2013
    9.3
    Critical

    CVE-2013-5456

    Last Modified: 11 Apr 2025

    The com.ibm.rmi.io.SunSerializableFactory class in IBM Java SDK 7.0.0 before SR6 allows remote attackers to bypass a sandbox protection mechanism and execute arbitrary code via vectors related to deserialization inside the AccessController doPrivileged block.

    Published: 5 Nov 2013
    9.3
    Critical

    CVE-2013-5457

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6, 6.0.1 before SR7, and 6.0.0 before SR15 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 5 Nov 2013
    9.3
    Critical

    CVE-2013-5458

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Java SDK 7.0.0 before SR6 allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 5 Nov 2013
    7.5
    High

    CVE-2013-4834

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the client component in HP Application LifeCycle Management (ALM) before 11 p11 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1327.

    Published: 4 Nov 2013
    7.5
    High

    CVE-2013-4835

    Last Modified: 11 Apr 2025

    The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.

    Published: 4 Nov 2013
    7.5
    High

    CVE-2013-4836

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the GossipService SOAP Request implementation in the Synchronizer component before 1.4.2 in HP Application LifeCycle Management (ALM) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1759.

    Published: 4 Nov 2013
    10
    Critical

    CVE-2013-4837

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.

    Published: 4 Nov 2013
    10
    Critical

    CVE-2013-4838

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1850.

    Published: 4 Nov 2013
    7.5
    High

    CVE-2013-4839

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors, aka ZDI-CAN-1851.

    Published: 4 Nov 2013
    6.8
    Medium

    CVE-2013-5559

    Last Modified: 11 Apr 2025

    Buffer overflow in the Active Template Library (ATL) framework in the VPNAPI COM module in Cisco AnyConnect Secure Mobility Client 2.x allows user-assisted remote attackers to execute arbitrary code via a crafted HTML document, aka Bug ID CSCuj58139.

    Published: 4 Nov 2013
    5
    Medium

    CVE-2013-5561

    Last Modified: 11 Apr 2025

    The Safe Search enforcement feature in Cisco Adaptive Security Appliance (ASA) CX Context-Aware Security Software does not properly perform filtering, which allows remote attackers to bypass intended policy restrictions via unspecified vectors, aka Bug ID CSCui94622.

    Published: 4 Nov 2013
    5
    Medium

    CVE-2013-5564

    Last Modified: 11 Apr 2025

    The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (process crash) via a flood of TCP packets, aka Bug ID CSCug57345.

    Published: 4 Nov 2013
    6.5
    Medium

    CVE-2013-6366

    Last Modified: 11 Apr 2025

    The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().exec call.

    Published: 4 Nov 2013
    5
    Medium

    CVE-2013-6114

    Last Modified: 11 Apr 2025

    Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denial of service (application crash) via a (1) large or (2) small value in the subview attribute of a viewer element in a .motn file.

    Published: 4 Nov 2013
    6.8
    Medium

    CVE-2013-6357

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator.

    Published: 4 Nov 2013
    4
    Medium

    CVE-2013-6800

    Last Modified: 11 Apr 2025

    An unspecified third-party database module for the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.10.x allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request, a different vulnerability than CVE-2013-1418.

    Published: 4 Nov 2013
    4.4
    Medium

    CVE-2013-6500

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 4 Nov 2013
    4.3
    Medium

    CVE-2013-1418

    Last Modified: 11 Apr 2025

    The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.

    Published: 4 Nov 2013
    5.8
    Medium

    CVE-2013-6171

    Last Modified: 11 Apr 2025

    checkpassword-reply in Dovecot before 2.2.7 performs setuid operations to a user who is authenticating, which allows local users to bypass authentication and access virtual email accounts by attaching to the process and using a restricted file descriptor to modify account information in the response to the dovecot-auth server.

    Published: 3 Nov 2013
    4.3
    Medium

    CVE-2013-6406

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-6858. Reason: This candidate is a reservation duplicate of CVE-2013-6858. Notes: All CVE users should reference CVE-2013-6858 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

    Published: 3 Nov 2013
    4.3
    Medium

    CVE-2013-6111

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the mod_pagespeed module 0.x, 1.0.22.7, 1.1.x, 1.24.1, 1.3.25.1 through 1.3.25.4, 1.4.26.1 through 1.4.26.4, 1.5.27.1 through 1.5.27.3, and 1.6.29.1 through 1.6.29.6 for the Apache HTTP Server allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Nov 2013
    8.5
    High

    CVE-2013-6349

    Last Modified: 11 Apr 2025

    McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors.

    Published: 2 Nov 2013
    7.8
    High

    CVE-2013-6023

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI.

    Published: 2 Nov 2013
    6.8
    Medium

    CVE-2013-6346

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 2 Nov 2013
    4.3
    Medium

    CVE-2013-6344

    Last Modified: 11 Apr 2025

    The ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows attackers to conduct cross-frame scripting attacks via unknown vectors.

    Published: 2 Nov 2013
    10
    Critical

    CVE-2013-6345

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors related to an "Application Exception."

    Published: 2 Nov 2013
    6.8
    Medium

    CVE-2013-6347

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors.

    Published: 2 Nov 2013
    5
    Medium

    CVE-2013-1084

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the GetFle method in the umaninv service in Novell ZENworks Configuration Management (ZCM) 11.2.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename parameter in a GetFile action to zenworks-unmaninv/.

    Published: 2 Nov 2013
    3.5
    Low

    CVE-2013-3285

    Last Modified: 11 Apr 2025

    The NetWorker Management Console (NMC) in EMC NetWorker 8.0.x before 8.0.2.3, when using Active Directory/LDAP for authentication, allows remote authenticated users to discover cleartext administrator passwords via (1) unspecified NMC audit reports or (2) requests to RAP resources.

    Published: 2 Nov 2013
    1.9
    Low

    CVE-2013-3287

    Last Modified: 11 Apr 2025

    EMC Unisphere for VMAX before 1.6.1.6, when using an unspecified level of debug logging in LDAP configurations, allows local users to discover the cleartext LDAP bind password by reading the console.

    Published: 2 Nov 2013
    3.5
    Low

    CVE-2013-3617

    Last Modified: 11 Apr 2025

    The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.

    Published: 2 Nov 2013
    6
    Medium

    CVE-2013-3631

    Last Modified: 11 Apr 2025

    NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execute Command" feature. NOTE: this issue might not be a vulnerability, since it appears to be part of legitimate, intentionally-exposed functionality by the developer and is allowed within the intended security policy.

    Published: 2 Nov 2013
    6.8
    Medium

    CVE-2013-4457

    Last Modified: 11 Apr 2025

    The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation.

    Published: 2 Nov 2013
    4.3
    Medium

    CVE-2013-2652

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in help/help_language.php in WebCollab 3.30 and earlier allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the item parameter.

    Published: 2 Nov 2013
    4.3
    Medium

    CVE-2013-4447

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the API in the Simplenews module 6.x-1.x before 6.x-1.5 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via an email address.

    Published: 1 Nov 2013
    6.8
    Medium

    CVE-2013-5977

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers to hijack the authentication of administrators for requests that (1) create or modify products or conduct cross-site scripting (XSS) attacks via the (2) Product name or (3) Price description field in a product save action via a request to wp-admin/admin.php.

    Published: 1 Nov 2013
    6.8
    Medium

    CVE-2013-2701

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Social Sharing Toolkit plugin 2.1.1 for WordPress allows remote attackers to hijack the authentication of administrators for requests that manipulate plugin settings via unknown vectors.

    Published: 1 Nov 2013
    5
    Medium

    CVE-2013-4484

    Last Modified: 11 Apr 2025

    Varnish before 3.0.5 allows remote attackers to cause a denial of service (child-process crash and temporary caching outage) via a GET request with trailing whitespace characters and no URI.

    Published: 1 Nov 2013
    4.6
    Medium

    CVE-2013-3630

    Last Modified: 11 Apr 2025

    Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.

    Published: 1 Nov 2013
    6.3
    Medium

    CVE-2013-5551

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software, when certain same-security-traffic and management-access options are enabled, allows remote authenticated users to cause a denial of service (stack overflow and device reload) by using the clientless SSL VPN portal for internal-resource browsing, aka Bug ID CSCui51199.

    Published: 1 Nov 2013
    3.5
    Low

    CVE-2013-4713

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware before 1.05e1-2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Nov 2013
    5.8
    Medium

    CVE-2013-5431

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in IBM Tivoli Federated Identity Manager (TFIM) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 and Tivoli Federated Identity Manager Business Gateway (TFIMBG) 6.1.1 before IF 15, 6.2.0 before IF 14, 6.2.1, and 6.2.2 before IF 8 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 1 Nov 2013
    4.3
    Medium

    CVE-2013-5548

    Last Modified: 11 Apr 2025

    The IKEv2 implementation in Cisco IOS, when AES-GCM or AES-GMAC is used, allows remote attackers to bypass certain IPsec anti-replay features via IPsec tunnel traffic, aka Bug ID CSCuj47795.

    Published: 1 Nov 2013
    4.3
    Medium

    CVE-2013-5555

    Last Modified: 11 Apr 2025

    Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to cause a denial of service (service restart) via a crafted SIP message, aka Bug ID CSCub54349.

    Published: 1 Nov 2013
    4.3
    Medium

    CVE-2013-6338

    Last Modified: 11 Apr 2025

    The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 1 Nov 2013
    5
    Medium

    CVE-2013-6076

    Last Modified: 11 Apr 2025

    strongSwan 5.0.2 through 5.1.0 allows remote attackers to cause a denial of service (NULL pointer dereference and charon daemon crash) via a crafted IKEv1 fragmentation packet.

    Published: 1 Nov 2013
    4.3
    Medium

    CVE-2013-6340

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly determine the amount of remaining data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 1 Nov 2013
    5.2
    Medium

    CVE-2013-4494

    Last Modified: 11 Apr 2025

    Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.

    Published: 1 Nov 2013