CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2013-3415

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliance (ASA) Software 8.4.x before 8.4(3) and 8.6.x before 8.6(1.3) does not properly manage memory upon an AnyConnect SSL VPN client disconnection, which allows remote attackers to cause a denial of service (memory consumption, and forwarding outage or system hang) via packets to the disconnected machine's IP address, aka Bug ID CSCtt36737.

    Published: 13 Oct 2013
    10
    Critical

    CVE-2013-4822

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1606.

    Published: 13 Oct 2013
    7.5
    High

    CVE-2013-4824

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to bypass authentication via unknown vectors, aka ZDI-CAN-1644.

    Published: 13 Oct 2013
    7.5
    High

    CVE-2013-4827

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in HP Intelligent Management Center (iMC) and HP IMC Service Operation Management Software Module allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka ZDI-CAN-1664.

    Published: 13 Oct 2013
    6.6
    Medium

    CVE-2013-5506

    Last Modified: 11 Apr 2025

    The authorization functionality in Cisco Firewall Services Module (FWSM) 3.1.x and 3.2.x before 3.2(25) and 4.x before 4.1(13), when multiple-context mode is enabled, allows local users to read or modify any context's configuration via unspecified commands, aka Bug ID CSCue46080.

    Published: 13 Oct 2013
    7.1
    High

    CVE-2013-5512

    Last Modified: 11 Apr 2025

    Race condition in the HTTP Deep Packet Inspection (DPI) feature in Cisco Adaptive Security Appliance (ASA) Software 8.2.x before 8.2(5.46), 8.3.x before 8.3(2.39), 8.4.x before 8.4(5.5), 8.5.x before 8.5(1.18), 8.6.x before 8.6(1.12), 8.7.x before 8.7(1.4), 9.0.x before 9.0(1.4), and 9.1.x before 9.1(1.2), in certain conditions involving the spoof-server option or ActiveX or Java response inspection, allows remote attackers to cause a denial of service (device reload) via a crafted HTTP response, aka Bug ID CSCud37992.

    Published: 13 Oct 2013
    6.9
    Medium

    CVE-2012-4709

    Last Modified: 11 Apr 2025

    Invensys Wonderware InTouch HMI 2012 R2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Published: 13 Oct 2013
    7.5
    High

    CVE-2013-4137

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."

    Published: 11 Oct 2013
    4.3
    Medium

    CVE-2013-4167

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) before 1.11.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 11 Oct 2013
    5
    Medium

    CVE-2013-4173

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitrary files via a .. (dot dot) in the host name in a "drophost" command.

    Published: 11 Oct 2013
    7.5
    High

    CVE-2013-4203

    Last Modified: 11 Apr 2025

    The self.run_gpg function in lib/rgpg/gpg_helper.rb in the rgpg gem before 0.2.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.

    Published: 11 Oct 2013
    9
    Critical

    CVE-2013-4319

    Last Modified: 11 Apr 2025

    pbs_mom in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.5.x, 4.x, and earlier does not properly restrict access by unprivileged ports, which allows remote authenticated users to execute arbitrary jobs by submitting a command.

    Published: 11 Oct 2013
    6.8
    Medium

    CVE-2013-4388

    Last Modified: 11 Apr 2025

    Buffer overflow in the mp4a packetizer (modules/packetizer/mpeg4audio.c) in VideoLAN VLC Media Player before 2.0.8 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.

    Published: 11 Oct 2013
    7.9
    High

    CVE-2013-3693

    Last Modified: 11 Apr 2025

    The BlackBerry Universal Device Service in BlackBerry Enterprise Service (BES) 10.0 through 10.1.2 does not properly restrict access to the JBoss Remote Method Invocation (RMI) interface, which allows remote attackers to upload and execute arbitrary packages via a request to port 1098.

    Published: 11 Oct 2013
    7.2
    High

    CVE-2013-6079

    Last Modified: 11 Apr 2025

    Buffer overflow in MostGear Soft Easy LAN Folder Share 3.2.0.100 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in the (1) registration code field in the activate license window or the (2) HKLM\SOFTWARE\MostGear\EasyLanFolderShare_V1\License registry key. NOTE: it is not clear from the original report whether this issue crosses privilege boundaries. If not, then it should not be included in CVE.

    Published: 11 Oct 2013
    4
    Medium

    CVE-2009-5136

    Last Modified: 11 Apr 2025

    The policy definition evaluator in Condor before 7.4.2 does not properly handle attributes in a WANT_SUSPEND policy that evaluate to an UNDEFINED state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.

    Published: 11 Oct 2013
    7.8
    High

    CVE-2013-2581

    Last Modified: 11 Apr 2025

    cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to modify the firmware revision via a "preset" action.

    Published: 11 Oct 2013
    6.8
    Medium

    CVE-2013-4306

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in api/ApiQueryCheckUser.php in the CheckUser extension for MediaWiki, possibly Checkuser before 2.3, allows remote attackers to hijack the authentication of arbitrary users for requests that "perform sensitive write actions" via unspecified vectors.

    Published: 11 Oct 2013
    6.5
    Medium

    CVE-2013-5028

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authenticated users to execute arbitrary SQL commands via the (1) hardwareType, (2) hardwareStatus, or (3) hardwareLocation parameter in a search command.

    Published: 11 Oct 2013
    10
    Critical

    CVE-2013-2579

    Last Modified: 11 Apr 2025

    TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty password for the hardcoded "qmik" account, which allows remote attackers to obtain administrative access via a TELNET session.

    Published: 11 Oct 2013
    7.1
    High

    CVE-2013-2580

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, allows remote attackers to upload arbitrary files, then accessing it via a direct request to the file in the mnt/mtd directory.

    Published: 11 Oct 2013
    10
    Critical

    CVE-2013-3686

    Last Modified: 11 Apr 2025

    cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list action.

    Published: 11 Oct 2013
    7.8
    High

    CVE-2013-3687

    Last Modified: 11 Apr 2025

    AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models use cleartext to store sensitive information, which allows attackers to obtain passwords, user names, and other sensitive information by reading an unspecified backup file.

    Published: 11 Oct 2013
    10
    Critical

    CVE-2013-2578

    Last Modified: 11 Apr 2025

    cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.

    Published: 11 Oct 2013
    4.3
    Medium

    CVE-2013-4305

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in contrib/example.php in the SyntaxHighlight GeSHi extension for MediaWiki, possibly as downloaded before September 2013, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 11 Oct 2013
    4
    Medium

    CVE-2013-5528

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815.

    Published: 11 Oct 2013
    5
    Medium

    CVE-2013-5532

    Last Modified: 11 Apr 2025

    Buffer overflow in the web-application interface on Cisco 9900 IP phones allows remote attackers to cause a denial of service (webapp interface outage) via long values in unspecified fields, aka Bug ID CSCuh10343.

    Published: 11 Oct 2013
    6
    Medium

    CVE-2013-5533

    Last Modified: 11 Apr 2025

    The image-upgrade functionality on Cisco 9900 Unified IP phones allows local users to gain privileges by placing shell commands in an unspecified parameter, aka Bug ID CSCuh10334.

    Published: 11 Oct 2013
    6.1
    Medium

    CVE-2013-7027

    Last Modified: 11 Apr 2025

    The ieee80211_radiotap_iterator_init function in net/wireless/radiotap.c in the Linux kernel before 3.11.7 does not check whether a frame contains any data outside of the header, which might allow attackers to cause a denial of service (buffer over-read) via a crafted header.

    Published: 11 Oct 2013
    5.8
    Medium

    CVE-2007-6755

    Last Modified: 11 Apr 2025

    The NIST SP 800-90A default statement of the Dual Elliptic Curve Deterministic Random Bit Generation (Dual_EC_DRBG) algorithm contains point Q constants with a possible relationship to certain "skeleton key" values, which might allow context-dependent attackers to defeat cryptographic protection mechanisms by leveraging knowledge of those values. NOTE: this is a preliminary CVE for Dual_EC_DRBG; future research may provide additional details about point Q and associated attacks, and could potentially lead to a RECAST or REJECT of this CVE.

    Published: 11 Oct 2013
    1.7
    Low

    CVE-2014-1444

    Last Modified: 11 Apr 2025

    The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCWANDEV ioctl call.

    Published: 11 Oct 2013
    4.3
    Medium

    CVE-2013-4449

    Last Modified: 11 Apr 2025

    The rwm overlay in OpenLDAP 2.4.23, 2.4.36, and earlier does not properly count references, which allows remote attackers to cause a denial of service (slapd crash) by unbinding immediately after a search request, which triggers rwm_conn_destroy to free the session context while it is being used by rwm_op_search.

    Published: 11 Oct 2013
    4.3
    Medium

    CVE-2013-0579

    Last Modified: 11 Apr 2025

    The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote attackers to impersonate arbitrary users by leveraging access to a legitimate user's web browser either (1) before or (2) after authentication.

    Published: 10 Oct 2013
    4.9
    Medium

    CVE-2013-0580

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to hijack the authentication of arbitrary users.

    Published: 10 Oct 2013
    4.3
    Medium

    CVE-2013-3409

    Last Modified: 11 Apr 2025

    The portal in Cisco Prime Central for Hosted Collaboration Solution (HCS) places cleartext credentials in temporary files, which allows local users to obtain sensitive information by leveraging weak file permissions to read these files, aka Bug IDs CSCuh33735 and CSCuh34230.

    Published: 10 Oct 2013
    4.6
    Medium

    CVE-2013-5008

    Last Modified: 11 Apr 2025

    The agent and task-agent components in Symantec Management Platform 7.0 and 7.1 before 7.1 SP2 Mp1.1v7 rollup, as used in certain Altiris products, use the same registry-entry encryption key across different customers' installations, which makes it easier for local users to obtain sensitive information about package-server access, or cause a denial of service, by leveraging knowledge of this key.

    Published: 10 Oct 2013
    5.7
    Medium

    CVE-2013-5499

    Last Modified: 11 Apr 2025

    The remember feature in the DHCP server in Cisco IOS allows remote attackers to cause a denial of service (device reload) by acquiring a lease and then sending a DHCPRELEASE message, aka Bug ID CSCuh46822.

    Published: 10 Oct 2013
    4.3
    Medium

    CVE-2013-5523

    Last Modified: 11 Apr 2025

    The Sponsor Portal in Cisco Identity Services Engine (ISE) 1.2 and earlier does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCui82666.

    Published: 10 Oct 2013
    4.3
    Medium

    CVE-2013-5524

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the troubleshooting page in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCug77655.

    Published: 10 Oct 2013
    6.5
    Medium

    CVE-2013-5525

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the web framework in Cisco Identity Services Engine (ISE) 1.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCug90502.

    Published: 10 Oct 2013
    7.1
    High

    CVE-2013-5526

    Last Modified: 11 Apr 2025

    Cisco 9900 fourth-generation IP phones do not properly perform SDP negotiation, which allows remote attackers to cause a denial of service (device reboot) via crafted SDP packets, aka Bug ID CSCuf06698.

    Published: 10 Oct 2013
    5.7
    Medium

    CVE-2013-5527

    Last Modified: 11 Apr 2025

    The OSPF functionality in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (device reload) via crafted options in an LSA type 11 packet, aka Bug ID CSCui21030.

    Published: 10 Oct 2013
    5.2
    Medium

    CVE-2013-0577

    Last Modified: 11 Apr 2025

    The Optim E-Business Console in IBM Data Growth Solution for Oracle E-business Suite 6.0 through 9.1 allows remote authenticated users to bypass intended access restrictions and create, modify, or delete documents or scripts via unspecified vectors.

    Published: 10 Oct 2013
    7.5
    High

    CVE-2013-2138

    Last Modified: 11 Apr 2025

    The (1) uploadify and (2) flowplayer SWF files in Gallery 3 before 3.0.8 do not properly remove query parameters and fragments, which allows remote attackers to have an unspecified impact via a replay attack.

    Published: 10 Oct 2013
    7.5
    High

    CVE-2013-2240

    Last Modified: 11 Apr 2025

    lib/flowplayer.swf.php in Gallery 3 before 3.0.9 does not properly remove query fragments, which allows remote attackers to have an unspecified impact via a replay attack, a different vulnerability than CVE-2013-2138.

    Published: 10 Oct 2013
    1.9
    Low

    CVE-2013-4368

    Last Modified: 11 Apr 2025

    The outs instruction emulation in Xen 3.1.x, 4.2.x, 4.3.x, and earlier, when using FS: or GS: segment override, uses an uninitialized variable as a segment base, which allows local 64-bit PV guests to obtain sensitive information (hypervisor stack content) via unspecified vectors related to stale data in a segment register.

    Published: 10 Oct 2013
    1.9
    Low

    CVE-2013-4369

    Last Modified: 11 Apr 2025

    The xlu_vif_parse_rate function in the libxlu library in Xen 4.2.x and 4.3.x allows local users to cause a denial of service (NULL pointer dereference) by using the "@" character as the VIF rate configuration.

    Published: 10 Oct 2013
    2.7
    Low

    CVE-2013-4375

    Last Modified: 11 Apr 2025

    The qdisk PV disk backend in qemu-xen in Xen 4.2.x and 4.3.x before 4.3.1, and qemu 1.1 and other versions, allows local HVM guests to cause a denial of service (domain grant reference consumption) via unspecified vectors.

    Published: 10 Oct 2013
    10
    Critical

    CVE-2013-4767

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Eucalyptus before 3.3.2 has unknown impact and attack vectors.

    Published: 10 Oct 2013
    5
    Medium

    CVE-2013-2241

    Last Modified: 11 Apr 2025

    modules/gallery/helpers/data_rest.php in Gallery 3 before 3.0.9 allows remote attackers to bypass intended access restrictions and obtain sensitive information (image files) via the "full" string in the size parameter.

    Published: 10 Oct 2013