CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2013-5171

    Last Modified: 11 Apr 2025

    CoreGraphics in Apple Mac OS X before 10.9 allows local users to bypass secure input mode and log an arbitrary application's keystrokes via a hotkey event registration.

    Published: 24 Oct 2013
    4.3
    Medium

    CVE-2013-5180

    Last Modified: 11 Apr 2025

    The srandomdev function in Libc in Apple Mac OS X before 10.9, when the kernel random-number generator is unavailable, produces predictable values instead of the intended random values, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of these values, related to a compiler-optimization issue.

    Published: 24 Oct 2013
    2.1
    Low

    CVE-2013-5186

    Last Modified: 11 Apr 2025

    Power Management in Apple Mac OS X before 10.9 does not properly handle the interaction between locking and power assertions, which allows physically proximate attackers to obtain sensitive information by reading a screen that should have transitioned into the locked state.

    Published: 24 Oct 2013
    5.8
    Medium

    CVE-2013-5189

    Last Modified: 11 Apr 2025

    Apple Mac OS X before 10.9 does not preserve a certain administrative system-preferences setting across software updates, which allows context-dependent attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended security configuration after the completion of an update.

    Published: 24 Oct 2013
    3.3
    Low

    CVE-2013-5144

    Last Modified: 11 Apr 2025

    Passcode Lock in Apple iOS before 7.0.3 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by tapping the emergency-call button during a certain notification and camera-pane state to trigger a NULL pointer dereference.

    Published: 24 Oct 2013
    3.3
    Low

    CVE-2013-5164

    Last Modified: 11 Apr 2025

    Multiple race conditions in the Phone app in Apple iOS before 7.0.3 allow physically proximate attackers to bypass the locked state, and dial the telephone numbers in arbitrary Contacts entries, by visiting the Contacts pane.

    Published: 24 Oct 2013
    6.4
    Medium

    CVE-2013-5165

    Last Modified: 11 Apr 2025

    socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers to bypass intended access restrictions via a network connection to an application for which blocking was configured.

    Published: 24 Oct 2013
    4.9
    Medium

    CVE-2013-5166

    Last Modified: 11 Apr 2025

    The Bluetooth USB host controller in Apple Mac OS X before 10.9 prematurely deletes interfaces, which allows local users to cause a denial of service (system crash) via a crafted application.

    Published: 24 Oct 2013
    5
    Medium

    CVE-2013-5167

    Last Modified: 11 Apr 2025

    CFNetwork in Apple Mac OS X before 10.9 does not properly support Safari's deletion of session cookies in response to a reset operation, which makes it easier for remote web servers to track users via Set-Cookie HTTP headers.

    Published: 24 Oct 2013
    6.8
    Medium

    CVE-2013-5168

    Last Modified: 11 Apr 2025

    Console in Apple Mac OS X before 10.9 allows user-assisted remote attackers to execute arbitrary applications by triggering a log entry with a crafted attached URL.

    Published: 24 Oct 2013
    1.9
    Low

    CVE-2013-5169

    Last Modified: 11 Apr 2025

    CoreGraphics in Apple Mac OS X before 10.9, when display-sleep mode is used, does not ensure that screen locking blocks the visibility of all windows, which allows physically proximate attackers to obtain sensitive information by reading the screen.

    Published: 24 Oct 2013
    6.8
    Medium

    CVE-2013-5170

    Last Modified: 11 Apr 2025

    Buffer underflow in CoreGraphics in Apple Mac OS X before 10.9 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted PDF document.

    Published: 24 Oct 2013
    7.1
    High

    CVE-2013-5172

    Last Modified: 11 Apr 2025

    The kernel in Apple Mac OS X before 10.9 does not properly determine the output length for SHA-2 digest function calls, which allows context-dependent attackers to cause a denial of service (panic) by triggering a digest operation, as demonstrated by an IPSec connection.

    Published: 24 Oct 2013
    2.1
    Low

    CVE-2013-5173

    Last Modified: 11 Apr 2025

    The random-number generator in the kernel in Apple Mac OS X before 10.9 provides lengthy exclusive access for processing of large requests, which allows local users to cause a denial of service (temporary generator outage) via an application that requires many random numbers.

    Published: 24 Oct 2013
    4.9
    Medium

    CVE-2013-5174

    Last Modified: 11 Apr 2025

    Integer signedness error in the kernel in Apple Mac OS X before 10.9 allows local users to cause a denial of service (system crash) via a crafted tty read operation.

    Published: 24 Oct 2013
    6.6
    Medium

    CVE-2013-5175

    Last Modified: 11 Apr 2025

    The kernel in Apple Mac OS X before 10.9 allows local users to obtain sensitive information or cause a denial of service (out-of-bounds read and system crash) via a crafted Mach-O file.

    Published: 24 Oct 2013
    4.9
    Medium

    CVE-2013-5176

    Last Modified: 11 Apr 2025

    The kernel in Apple Mac OS X before 10.9 does not properly handle integer values during unspecified tty device operations, which allows local users to cause a denial of service (system hang) by triggering a truncation error.

    Published: 24 Oct 2013
    4.9
    Medium

    CVE-2013-5177

    Last Modified: 11 Apr 2025

    The kernel in Apple Mac OS X before 10.9 allows local users to cause a denial of service (panic) via an invalid iovec structure.

    Published: 24 Oct 2013
    5
    Medium

    CVE-2013-5178

    Last Modified: 11 Apr 2025

    LaunchServices in Apple Mac OS X before 10.9 does not properly restrict Unicode characters in filenames, which allows context-dependent attackers to spoof file extensions via a crafted character sequence.

    Published: 24 Oct 2013
    7.5
    High

    CVE-2013-5179

    Last Modified: 11 Apr 2025

    App Sandbox in Apple Mac OS X before 10.9 allows attackers to bypass intended sandbox restrictions via a crafted app that uses the LaunchServices interface to specify process arguments.

    Published: 24 Oct 2013
    5
    Medium

    CVE-2013-5182

    Last Modified: 11 Apr 2025

    Mail in Apple Mac OS X before 10.9 allows remote attackers to spoof the existence of a cryptographic signature for an e-mail message by using the multipart/signed content type within an unsigned message.

    Published: 24 Oct 2013
    2.6
    Low

    CVE-2013-5183

    Last Modified: 11 Apr 2025

    Mail in Apple Mac OS X before 10.9, when Kerberos authentication is enabled and TLS is disabled, sends invalid cleartext data, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 24 Oct 2013
    5.7
    Medium

    CVE-2013-5184

    Last Modified: 11 Apr 2025

    The kernel in Apple Mac OS X before 10.9 does not properly check for errors during the processing of multicast Wi-Fi packets, which allows remote attackers to cause a denial of service (system crash) by leveraging presence in an 802.11 network's coverage area.

    Published: 24 Oct 2013
    4.3
    Medium

    CVE-2013-5185

    Last Modified: 11 Apr 2025

    The ldapsearch command-line program in OpenLDAP in Apple Mac OS X before 10.9 does not properly process the minssf configuration setting, which allows remote attackers to obtain sensitive information by leveraging unintended weak encryption and sniffing the network.

    Published: 24 Oct 2013
    1.9
    Low

    CVE-2013-5187

    Last Modified: 11 Apr 2025

    The Screen Lock implementation in Apple Mac OS X before 10.9 does not immediately accept Keychain Status menu Lock Screen commands, and instead incorrectly relies on a certain timeout setting, which allows physically proximate attackers to obtain sensitive information by reading a screen that should have transitioned into the locked state.

    Published: 24 Oct 2013
    4
    Medium

    CVE-2013-5188

    Last Modified: 11 Apr 2025

    The Screen Lock implementation in Apple Mac OS X before 10.9, when hibernation and autologin are enabled, does not require a password for a transition out of hibernation, which allows physically proximate attackers to obtain access by visiting an unattended workstation in the hibernating state.

    Published: 24 Oct 2013
    4.3
    Medium

    CVE-2013-5190

    Last Modified: 11 Apr 2025

    Smart Card Services in Apple Mac OS X before 10.9 does not properly implement certificate-revocation checks, which allows remote attackers to cause a denial of service (Smart Card usage outage) by interfering with the revocation-check procedure.

    Published: 24 Oct 2013
    2.1
    Low

    CVE-2013-5191

    Last Modified: 11 Apr 2025

    The syslog implementation in Apple Mac OS X before 10.9 allows local users to obtain sensitive information by leveraging access to the Guest account and reading console-log messages from previous Guest sessions.

    Published: 24 Oct 2013
    4.9
    Medium

    CVE-2013-5192

    Last Modified: 11 Apr 2025

    The USB hub controller in Apple Mac OS X before 10.9 allows local users to cause a denial of service (system crash) via a request with a crafted (1) port or (2) port number.

    Published: 24 Oct 2013
    5
    Medium

    CVE-2013-6246

    Last Modified: 11 Apr 2025

    The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full name) by sending a login request with a valid domain and username but without the CaptchaType, UseCaptchaEveryTime, and CaptchaResponse parameters.

    Published: 24 Oct 2013
    4.3
    Medium

    CVE-2013-5136

    Last Modified: 11 Apr 2025

    Apple Remote Desktop before 3.7 does not properly use server authentication-type information during decisions about whether to present an unencrypted-connection warning message, which allows remote attackers to obtain sensitive information in opportunistic circumstances by sniffing the network during an unintended cleartext VNC session.

    Published: 24 Oct 2013
    4.3
    Medium

    CVE-2013-5181

    Last Modified: 11 Apr 2025

    The auto-configuration feature in Mail in Apple Mac OS X before 10.9 selects plaintext authentication for unspecified servers that support CRAM-MD5 authentication, which allows remote attackers to obtain sensitive information by sniffing the network.

    Published: 24 Oct 2013
    9.1
    Critical

    CVE-2013-4561

    Last Modified: 21 Nov 2024

    In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.

    Published: 24 Oct 2013
    6
    Medium

    CVE-2013-3244

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the CJDB_FILL_MEMORY_FROM_PPB function in the Project System (PS-IS) module for SAP ERP Central Component (ECC) allow remote attackers to execute arbitrary code via a (1) RFC or (2) SOAP-RFC request.

    Published: 24 Oct 2013
    10
    Critical

    CVE-2013-6245

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 24 Oct 2013
    5
    Medium

    CVE-2013-6244

    Last Modified: 11 Apr 2025

    The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to read arbitrary files and directories via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 24 Oct 2013
    6.8
    Medium

    CVE-2013-4422

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Quassel IRC before 0.9.1, when Qt 4.8.5 or later and PostgreSQL 8.2 or later are used, allows remote attackers to execute arbitrary SQL commands via a \ (backslash) in a message.

    Published: 23 Oct 2013
    7.5
    High

    CVE-2013-6243

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.php.

    Published: 23 Oct 2013
    4.3
    Medium

    CVE-2013-2651

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in BoltWire 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) "p" or (2) content parameter to index.php.

    Published: 23 Oct 2013
    5
    Medium

    CVE-2013-4466

    Last Modified: 11 Apr 2025

    Buffer overflow in the dane_query_tlsa function in the DANE library (libdane) in GnuTLS 3.1.x before 3.1.15 and 3.2.x before 3.2.5 allows remote servers to cause a denial of service (memory corruption) via a response with more than four DANE entries.

    Published: 23 Oct 2013
    6.8
    Medium

    CVE-2013-5703

    Last Modified: 11 Apr 2025

    The DrayTek Vigor 2700 router 2.8.3 allows remote attackers to execute arbitrary JavaScript code, and modify settings or the DNS cache, via a crafted SSID value that is not properly handled during insertion into the sWlessSurvey value in variables.js.

    Published: 22 Oct 2013
    4.3
    Medium

    CVE-2013-5388

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3 before FP5 IF2 and 9.0 before IF5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9AYK5F.

    Published: 22 Oct 2013
    4.3
    Medium

    CVE-2013-5389

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in iNotes in IBM Domino 8.5.3 before FP5 IF2 and 9.0 before IF5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN9AYK2X.

    Published: 22 Oct 2013
    10
    Critical

    CVE-2013-5446

    Last Modified: 11 Apr 2025

    The console on IBM WebSphere DataPower XC10 appliances 2.1.0 and 2.5.0 does not properly process logoff actions, which has unspecified impact and remote attack vectors.

    Published: 22 Oct 2013
    4.6
    Medium

    CVE-2013-5550

    Last Modified: 11 Apr 2025

    The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to cause a denial of service via crafted command parameters that trigger hardware-component write operations, aka Bug ID CSCtq86549.

    Published: 22 Oct 2013
    7.1
    High

    CVE-2013-5428

    Last Modified: 11 Apr 2025

    IBM WebSphere DataPower XC10 appliances 2.5.0 do not require authentication for all administrative actions, which allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 22 Oct 2013
    5.4
    Medium

    CVE-2013-5544

    Last Modified: 11 Apr 2025

    The VPN authentication functionality in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to cause a denial of service (device reload) by sending many username-from-cert IKE requests, aka Bug ID CSCua91108.

    Published: 22 Oct 2013
    5
    Medium

    CVE-2013-4458

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that triggers a large number of AF_INET6 address results. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-1914.

    Published: 22 Oct 2013
    Unknown

    CVE-2013-4381

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5938. Reason: This candidate is a duplicate of CVE-2013-5938. Notes: All CVE users should reference CVE-2013-5938 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Oct 2013
    Unknown

    CVE-2013-4382

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5937. Reason: This candidate is a duplicate of CVE-2013-5937. Notes: All CVE users should reference CVE-2013-5937 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Oct 2013