CVE Feed

    Dashboard / CVE

    5.8
    Medium

    CVE-2012-4115

    Last Modified: 11 Apr 2025

    The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM virtual-media data, which allows man-in-the-middle attackers to obtain sensitive information by sniffing the network or modify this traffic by inserting packets into the client-server data stream, aka Bug ID CSCtr72964.

    Published: 21 Oct 2013
    8.5
    High

    CVE-2013-5542

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software 8.4 before 8.4(7.2), 8.7 before 8.7(1.8), 9.0 before 9.0(3.6), and 9.1 before 9.1(2.8) allows remote attackers to cause a denial of service (firewall-session disruption or device reload) via crafted ICMP packets, aka Bug ID CSCui77398.

    Published: 21 Oct 2013
    7.1
    High

    CVE-2013-5970

    Last Modified: 11 Apr 2025

    hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by modifying management traffic.

    Published: 21 Oct 2013
    6.8
    Medium

    CVE-2013-5971

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.

    Published: 21 Oct 2013
    2.1
    Low

    CVE-2013-4293

    Last Modified: 11 Apr 2025

    The server in Red Hat JBoss Operations Network (JON) 3.1.2 logs passwords in plaintext, which allows local users to obtain sensitive information by reading the log files.

    Published: 21 Oct 2013
    3.2
    Low

    CVE-2013-4373

    Last Modified: 11 Apr 2025

    The storeFiles method in JPADriftServerBean in Red Hat JBoss Operations Network (JON) 3.1.2 allows local users to load arbitrary drift files into a server by writing the files to the temporary directory that is used to unpack zip files.

    Published: 21 Oct 2013
    7.2
    High

    CVE-2013-4400

    Last Modified: 11 Apr 2025

    virt-login-shell in libvirt 1.1.2 through 1.1.3 allows local users to overwrite arbitrary files and possibly gain privileges via unspecified environment variables or command-line arguments.

    Published: 21 Oct 2013
    8.5
    High

    CVE-2013-4401

    Last Modified: 11 Apr 2025

    The virConnectDomainXMLToNative API function in libvirt 1.1.0 through 1.1.3 checks for the connect:read permission instead of the connect:write permission, which allows attackers to gain domain:write privileges and execute Qemu binaries via crafted XML. NOTE: some of these details are obtained from third party information.

    Published: 21 Oct 2013
    2.1
    Low

    CVE-2013-4455

    Last Modified: 12 Apr 2025

    Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file.

    Published: 21 Oct 2013
    6.9
    Medium

    CVE-2013-4470

    Last Modified: 11 Apr 2025

    The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data structures, which allows local users to cause a denial of service (memory corruption and system crash) or possibly gain privileges via a crafted application that uses the UDP_CORK option in a setsockopt system call and sends both short and long packets, related to the ip_ufo_append_data function in net/ipv4/ip_output.c and the ip6_ufo_append_data function in net/ipv6/ip6_output.c.

    Published: 21 Oct 2013
    3.3
    Low

    CVE-2013-4477

    Last Modified: 11 Apr 2025

    The LDAP backend in OpenStack Identity (Keystone) Grizzly and Havana, when removing a role on a tenant for a user who does not have that role, adds the role to the user, which allows local users to gain privileges.

    Published: 21 Oct 2013
    5.5
    Medium

    CVE-2013-5653

    Last Modified: 20 Apr 2025

    The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.

    Published: 21 Oct 2013
    6.8
    Medium

    CVE-2013-4712

    Last Modified: 11 Apr 2025

    I-O DATA DEVICE HDL-A and HDL2-A devices with firmware 1.07 and earlier do not properly manage sessions, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

    Published: 19 Oct 2013
    6.8
    Medium

    CVE-2012-4112

    Last Modified: 11 Apr 2025

    The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and execute arbitrary commands via crafted command parameters within the command-line interface, aka Bug ID CSCtr43330.

    Published: 19 Oct 2013
    4.6
    Medium

    CVE-2012-4113

    Last Modified: 11 Apr 2025

    The fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges and read arbitrary files via crafted command parameters within the command-line interface, aka Bug ID CSCtr43374.

    Published: 19 Oct 2013
    5.8
    Medium

    CVE-2012-4114

    Last Modified: 11 Apr 2025

    The fabric-interconnect KVM module in Cisco Unified Computing System (UCS) does not encrypt video data, which allows man-in-the-middle attackers to watch KVM display content by sniffing the network or modify this traffic by inserting packets into the client-server data stream, aka Bug ID CSCtr72949.

    Published: 19 Oct 2013
    4.3
    Medium

    CVE-2012-4116

    Last Modified: 11 Apr 2025

    The fabric-interconnect component in Cisco Unified Computing System (UCS) does not encrypt KVM media traffic, which allows remote attackers to obtain sensitive information, and consequently complete the authentication process for a server connection, by sniffing the network, aka Bug ID CSCtr72970.

    Published: 19 Oct 2013
    5.8
    Medium

    CVE-2012-4117

    Last Modified: 11 Apr 2025

    The fabric-interconnect component in Cisco Unified Computing System (UCS) does not properly verify X.509 certificates, which allows man-in-the-middle attackers to watch SSL KVM video-channel traffic or modify this traffic via a crafted certificate, aka Bug ID CSCtr73033.

    Published: 19 Oct 2013
    4
    Medium

    CVE-2013-5534

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the attachment service in the Voice Message Web Service (aka VMWS or Cisco Unity Web Service) in Cisco Unity Connection allows remote authenticated users to create files, and consequently execute arbitrary JSP code, via a crafted pathname for a file that is not a valid audio file, aka Bug ID CSCuj22948.

    Published: 19 Oct 2013
    4.3
    Medium

    CVE-2013-5702

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WebCenter in WatchGuard WSM and Fireware before 11.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

    Published: 19 Oct 2013
    9.3
    Critical

    CVE-2013-6021

    Last Modified: 11 Apr 2025

    Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in a cookie.

    Published: 19 Oct 2013
    4
    Medium

    CVE-2013-6025

    Last Modified: 11 Apr 2025

    The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL statement containing an XML document with an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 19 Oct 2013
    8.5
    High

    CVE-2013-6027

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrators to execute arbitrary commands via a long set/runtime/diagnostic/pingIp parameter to Tools/tools_misc.xgi.

    Published: 19 Oct 2013
    7.5
    High

    CVE-2013-6129

    Last Modified: 11 Apr 2025

    The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013.

    Published: 19 Oct 2013
    4.3
    Medium

    CVE-2013-5372

    Last Modified: 11 Apr 2025

    The XML4J parser in IBM WebSphere Message Broker 6.1 before 6.1.0.12, 7.0 before 7.0.0.7, and 8.0 before 8.0.0.4 and IBM Integration Bus 9.0 before 9.0.0.1 allows remote attackers to cause a denial of service (memory consumption) via a crafted XML document that triggers expansion for many entities.

    Published: 19 Oct 2013
    10
    Critical

    CVE-2013-6026

    Last Modified: 11 Apr 2025

    The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows remote attackers to bypass authentication and modify settings via an xmlset_roodkcableoj28840ybtide User-Agent HTTP header, as exploited in the wild in October 2013.

    Published: 19 Oct 2013
    5.9
    Medium

    CVE-2013-7470

    Last Modified: 21 Nov 2024

    cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.

    Published: 19 Oct 2013
    5
    Medium

    CVE-2013-5704

    Last Modified: 12 Apr 2025

    The mod_headers module in the Apache HTTP Server 2.2.22 allows remote attackers to bypass "RequestHeader unset" directives by placing a header in the trailer portion of data sent with chunked transfer coding. NOTE: the vendor states "this is not a security issue in httpd as such."

    Published: 19 Oct 2013
    5
    Medium

    CVE-2013-4450

    Last Modified: 11 Apr 2025

    The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consumption) by sending a large number of pipelined requests without reading the response.

    Published: 18 Oct 2013
    5.1
    Medium

    CVE-2013-4689

    Last Modified: 11 Apr 2025

    J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1R before 12.1R6, 12.1X44 before 12.1X44-D15, 12.1x45 before 12.1X45-D10, 12.2 before 12.2R3, 12.3 before 12.3R2, and 13.1 before 13.1R3 allow remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism and hijack the authentication of administrators for requests that (1) create new administrator accounts or (2) have other unspecified impacts.

    Published: 17 Oct 2013
    4.3
    Medium

    CVE-2013-6169

    Last Modified: 11 Apr 2025

    The TLS driver in ejabberd before 2.1.12 supports (1) SSLv2 and (2) weak SSL ciphers, which makes it easier for remote attackers to obtain sensitive information via a brute-force attack.

    Published: 17 Oct 2013
    5
    Medium

    CVE-2013-2254

    Last Modified: 11 Apr 2025

    The deepGetOrCreateNode function in impl/operations/AbstractCreateOperation.java in org.apache.sling.servlets.post.bundle 2.2.0 and 2.3.0 in Apache Sling does not properly handle a NULL value that returned when the session does not have permissions to the root node, which allows remote attackers to cause a denial of service (infinite loop) via unspecified vectors.

    Published: 17 Oct 2013
    6.8
    Medium

    CVE-2013-6013

    Last Modified: 11 Apr 2025

    Buffer overflow in the flow daemon (flowd) in Juniper Junos 10.4 before 10.4S14, 11.4 before 11.4R7-S2, 12.1.X44 before 12.1X44-D15, 12.1X45 before 12.1X45-D10 on SRX devices, when using telnet pass-through authentication on the firewall, might allow remote attackers to execute arbitrary code via a crafted telnet message.

    Published: 17 Oct 2013
    4.3
    Medium

    CVE-2013-6015

    Last Modified: 11 Apr 2025

    Juniper Junos before 10.4S14, 11.4 before 11.4R5-S2, 12.1R before 12.1R3, 12.1X44 before 12.1X44-D20, and 12.1X45 before 12.1X45-D15 on SRX Series services gateways, when a plugin using TCP proxy is configured, allows remote attackers to cause a denial of service (flow daemon crash) via an unspecified sequence of TCP packets.

    Published: 17 Oct 2013
    4.3
    Medium

    CVE-2013-6170

    Last Modified: 11 Apr 2025

    Juniper Junos 10.0 before 10.0S28, 10.4 before 10.4R7, 11.1 before 11.1R5, 11.2 before 11.2R2, and 11.4 before 11.4R1, when in a Next-Generation Multicast VPN (NGEN MVPN) environment, allows remote attackers to cause a denial of service (RPD routing daemon crash) via a large number of crafted PIM (S,G) join requests.

    Published: 17 Oct 2013
    1.9
    Low

    CVE-2013-1056

    Last Modified: 11 Apr 2025

    X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.

    Published: 17 Oct 2013
    5
    Medium

    CVE-2013-1739

    Last Modified: 11 Apr 2025

    Mozilla Network Security Services (NSS) before 3.15.2 does not ensure that data structures are initialized before read operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a decryption failure.

    Published: 17 Oct 2013
    4.3
    Medium

    CVE-2013-3025

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Rational Focal Point 6.5.x and 6.6.x before 6.6.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Oct 2013
    4.3
    Medium

    CVE-2013-5376

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, related to a "cross frame scripting" attack against an administrative user.

    Published: 17 Oct 2013
    5.4
    Medium

    CVE-2013-0500

    Last Modified: 11 Apr 2025

    IBM Storwize V7000 Unified 1.3.x and 1.4.x before 1.4.2.0 does not properly handle device files that are created with the NFS protocol but accessed with a non-NFS protocol, which allows remote authenticated users to obtain sensitive information, modify programs or files, or cause a denial of service (device crash) via a (1) CIFS, (2) HTTPS, (3) SCP, or (4) SFTP operation.

    Published: 17 Oct 2013
    4.3
    Medium

    CVE-2013-1445

    Last Modified: 11 Apr 2025

    The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging a race condition in which a child process is created and accesses the PRNG within the same rate-limit period as another process.

    Published: 17 Oct 2013
    6.8
    Medium

    CVE-2013-4419

    Last Modified: 11 Apr 2025

    The guestfish command in libguestfs 1.20.12, 1.22.7, and earlier, when using the --remote or --listen option, does not properly check the ownership of /tmp/.guestfish-$UID/ when creating a temporary socket file in this directory, which allows local users to write to the socket and execute arbitrary commands by creating /tmp/.guestfish-$UID/ in advance.

    Published: 17 Oct 2013
    6.8
    Medium

    CVE-2013-2925

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in core/xml/XMLHttpRequest.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger multiple conflicting uses of the same XMLHttpRequest object.

    Published: 16 Oct 2013
    6.8
    Medium

    CVE-2013-2926

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the IndentOutdentCommand::tryIndentingAsListItem function in core/editing/IndentOutdentCommand.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows user-assisted remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to list elements.

    Published: 16 Oct 2013
    7.5
    High

    CVE-2013-2928

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 30.0.1599.101 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 16 Oct 2013
    6.8
    Medium

    CVE-2013-2927

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to submission for FORM elements.

    Published: 16 Oct 2013
    5
    Medium

    CVE-2013-3279

    Last Modified: 11 Apr 2025

    EMC Atmos before 2.1.4 has a blank password for the PostgreSQL account, which allows remote attackers to obtain sensitive administrative information via a database-server connection.

    Published: 16 Oct 2013
    4.9
    Medium

    CVE-2013-5862

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Solaris 10 and 11.1 allows local users to affect availability via vectors related to CPU performance counters (CPC) drivers, a different vulnerability than CVE-2014-4215.

    Published: 16 Oct 2013
    3.6
    Low

    CVE-2013-5856

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, 5.0 SP1a-b, 5.5 SP0, 5.5 SP0b, 5.5.1, and 6.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web.

    Published: 16 Oct 2013
    3.6
    Low

    CVE-2013-5857

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Health Sciences InForm component in Oracle Industry Applications 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, and 5.0 SP1a-b allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Web.

    Published: 16 Oct 2013