CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2013-5701

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in (1) Watchguard Log Collector (wlcollector.exe) and (2) Watchguard WebBlocker Server (wbserver.exe) in WatchGuard Server Center 11.7.4, 11.7.3, and possibly earlier allow local users to gain privileges via a Trojan horse wgpr.dll file in the application's bin directory.

    Published: 3 Oct 2013
    4.3
    Medium

    CVE-2013-6010

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Comment Attachment plugin 1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "Attachment field title."

    Published: 3 Oct 2013
    3.5
    Low

    CVE-2013-5690

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite before 7.2.2 allow remote authenticated users to inject arbitrary web script or HTML via (1) content with the text/xml MIME type or (2) the Status comment field of an appointment.

    Published: 3 Oct 2013
    4.3
    Medium

    CVE-2013-6009

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in Open-Xchange AppSuite before 7.2.2, when using AJP in certain conditions, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the ajax/defer servlet.

    Published: 3 Oct 2013
    10
    Critical

    CVE-2013-0689

    Last Modified: 11 Apr 2025

    The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitrary code via unspecified vectors.

    Published: 3 Oct 2013
    10
    Critical

    CVE-2013-5944

    Last Modified: 11 Apr 2025

    The integrated web server on Siemens SCALANCE X-200 switches with firmware before 4.5.0 and X-200IRT switches with firmware before 5.1.0 does not properly enforce authentication requirements, which allows remote attackers to perform administrative actions via requests to the management interface.

    Published: 3 Oct 2013
    10
    Critical

    CVE-2013-0693

    Last Modified: 11 Apr 2025

    The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadcasts, which allows remote attackers to obtain potentially sensitive information about device presence by listening for broadcast traffic.

    Published: 3 Oct 2013
    7.8
    High

    CVE-2013-3593

    Last Modified: 11 Apr 2025

    Baramundi Management Suite 7.5 through 8.9 uses cleartext for (1) client-server communication and (2) data storage, which allows remote attackers to obtain sensitive information by sniffing the network, and allows context-dependent attackers to obtain sensitive information by reading a file.

    Published: 3 Oct 2013
    7.8
    High

    CVE-2013-3624

    Last Modified: 11 Apr 2025

    The OS deployment feature in Baramundi Management Suite 7.5 through 8.9 stores credentials in cleartext on deployed machines, which allows remote attackers to obtain sensitive information by reading a file. NOTE: this ID was also incorrectly mapped to a separate issue in Oracle Outside In, but the correct ID for that issue is CVE-2013-5763.

    Published: 3 Oct 2013
    4.3
    Medium

    CVE-2013-5519

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management interface on Cisco Wireless LAN Controller (WLC) devices allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCuf77810.

    Published: 3 Oct 2013
    6.8
    Medium

    CVE-2012-4136

    Last Modified: 11 Apr 2025

    The high-availability service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) does not properly bind the cluster service to the management interface, which allows remote attackers to obtain sensitive information or cause a denial of service (peer-syncing outage) via a TELNET connection, aka Bug ID CSCtz72910.

    Published: 3 Oct 2013
    10
    Critical

    CVE-2013-0692

    Last Modified: 11 Apr 2025

    The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service.

    Published: 3 Oct 2013
    9
    Critical

    CVE-2013-0694

    Last Modified: 11 Apr 2025

    The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier have hardcoded credentials in a ROM, which makes it easier for remote attackers to obtain shell access to the underlying OS by leveraging knowledge of the ROM contents from a product installation elsewhere.

    Published: 3 Oct 2013
    7.8
    High

    CVE-2013-3625

    Last Modified: 11 Apr 2025

    An unspecified DLL file in Baramundi Management Suite 7.5 through 8.9 uses a hardcoded encryption key, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from a product installation elsewhere.

    Published: 3 Oct 2013
    5
    Medium

    CVE-2013-6438

    Last Modified: 12 Apr 2025

    The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.

    Published: 3 Oct 2013
    6.8
    Medium

    CVE-2012-4110

    Last Modified: 11 Apr 2025

    run-script in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq86560.

    Published: 2 Oct 2013
    4.3
    Medium

    CVE-2013-4066

    Last Modified: 11 Apr 2025

    IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to conduct clickjacking attacks by creating an overlay interface on top of the Web Console interface.

    Published: 2 Oct 2013
    5.5
    Medium

    CVE-2012-4095

    Last Modified: 11 Apr 2025

    The local file editor in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges, and read or modify arbitrary files, via unspecified key bindings, aka Bug ID CSCtn04521.

    Published: 2 Oct 2013
    6.6
    Medium

    CVE-2012-4104

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in the image-download process in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to overwrite or delete arbitrary files via a full pathname in an image header, aka Bug ID CSCtq02706.

    Published: 2 Oct 2013
    7.8
    High

    CVE-2013-5503

    Last Modified: 11 Apr 2025

    The UDP process in Cisco IOS XR 4.3.1 does not free packet memory upon detecting full packet queues, which allows remote attackers to cause a denial of service (memory consumption) via UDP packets to listening ports, aka Bug ID CSCue69413.

    Published: 2 Oct 2013
    5.5
    Medium

    CVE-2013-5517

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the web framework in Cisco Unified Communications Domain Manager allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh96567.

    Published: 2 Oct 2013
    6.8
    Medium

    CVE-2012-4102

    Last Modified: 11 Apr 2025

    The activate firmware command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq02600.

    Published: 2 Oct 2013
    6.8
    Medium

    CVE-2012-4109

    Last Modified: 11 Apr 2025

    The clear sshkey command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq86559.

    Published: 2 Oct 2013
    6.8
    Medium

    CVE-2012-4111

    Last Modified: 11 Apr 2025

    The create certreq command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq86563.

    Published: 2 Oct 2013
    5.8
    Medium

    CVE-2013-4067

    Last Modified: 11 Apr 2025

    IBM InfoSphere Information Server 8.0, 8.1, 8.5 through FP3, 8.7, and 9.1 allows remote attackers to hijack sessions and read cookie values, or conduct phishing attacks to capture credentials, via unspecified vectors.

    Published: 2 Oct 2013
    5
    Medium

    CVE-2013-5979

    Last Modified: 8 Dec 2025

    Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php.

    Published: 2 Oct 2013
    6.8
    Medium

    CVE-2012-4103

    Last Modified: 11 Apr 2025

    ethanalyzer in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq02686.

    Published: 2 Oct 2013
    Unknown

    CVE-2012-2497

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-3497, CVE-2012-6400. Reason: This candidate is a duplicate of CVE-2012-3497 and CVE-2012-6400. Notes: All CVE users should reference CVE-2012-3497 (an issue in Xen) or CVE-2012-6400 (an issue not in Xen) instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 2 Oct 2013
    6.8
    Medium

    CVE-2013-2911

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the XSLStyleSheet::compileStyleSheet function in core/xml/XSLStyleSheetLibxslt.cpp in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging improper handling of post-failure recompilation in unspecified libxslt versions.

    Published: 2 Oct 2013
    6.8
    Medium

    CVE-2013-2921

    Last Modified: 11 Apr 2025

    Double free vulnerability in the ResourceFetcher::didLoadResource function in core/fetch/ResourceFetcher.cpp in the resource loader in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact by triggering certain callback processing during the reporting of a resource entry.

    Published: 2 Oct 2013
    5
    Medium

    CVE-2013-4032

    Last Modified: 11 Apr 2025

    The Fast Communications Manager (FCM) in IBM DB2 Enterprise Server Edition and Advanced Enterprise Server Edition 10.1 before FP3 and 10.5, when a multi-node configuration is used, allows remote attackers to cause a denial of service via vectors involving arbitrary data.

    Published: 2 Oct 2013
    6.8
    Medium

    CVE-2013-2906

    Last Modified: 11 Apr 2025

    Multiple race conditions in the Web Audio implementation in Blink, as used in Google Chrome before 30.0.1599.66, allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to threading in core/html/HTMLMediaElement.cpp, core/platform/audio/AudioDSPKernelProcessor.cpp, core/platform/audio/HRTFElevation.cpp, and modules/webaudio/ConvolverNode.cpp.

    Published: 2 Oct 2013
    5
    Medium

    CVE-2013-2907

    Last Modified: 11 Apr 2025

    The Window.prototype object implementation in Google Chrome before 30.0.1599.66 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 2 Oct 2013
    5
    Medium

    CVE-2013-2908

    Last Modified: 11 Apr 2025

    Google Chrome before 30.0.1599.66 uses incorrect function calls to determine the values of NavigationEntry objects, which allows remote attackers to spoof the address bar via vectors involving a response with a 204 (aka No Content) status code.

    Published: 2 Oct 2013
    7.5
    High

    CVE-2013-2909

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to inline-block rendering for bidirectional Unicode text in an element isolated from its siblings.

    Published: 2 Oct 2013
    7.5
    High

    CVE-2013-2910

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in modules/webaudio/AudioScheduledSourceNode.cpp in the Web Audio implementation in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 2 Oct 2013
    6.8
    Medium

    CVE-2013-2913

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the XMLDocumentParser::append function in core/xml/parser/XMLDocumentParser.cpp in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an XML document.

    Published: 2 Oct 2013
    6.8
    Medium

    CVE-2013-2914

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the color-chooser dialog in Google Chrome before 30.0.1599.66 on Windows allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to color_chooser_dialog.cc and color_chooser_win.cc in browser/ui/views/.

    Published: 2 Oct 2013
    4.3
    Medium

    CVE-2013-2915

    Last Modified: 11 Apr 2025

    Google Chrome before 30.0.1599.66 preserves pending NavigationEntry objects in certain invalid circumstances, which allows remote attackers to spoof the address bar via a URL with a malformed scheme, as demonstrated by a nonexistent:12121 URL.

    Published: 2 Oct 2013
    4.3
    Medium

    CVE-2013-2916

    Last Modified: 11 Apr 2025

    Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to spoof the address bar via vectors involving a response with a 204 (aka No Content) status code, in conjunction with a delay in notifying the user of an attempted spoof.

    Published: 2 Oct 2013
    5
    Medium

    CVE-2013-2917

    Last Modified: 11 Apr 2025

    The ReverbConvolverStage::ReverbConvolverStage function in core/platform/audio/ReverbConvolverStage.cpp in the Web Audio implementation in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the impulseResponse array.

    Published: 2 Oct 2013
    5
    Medium

    CVE-2013-2920

    Last Modified: 11 Apr 2025

    The DoResolveRelativeHost function in url/url_canon_relative.cc in Google Chrome before 30.0.1599.66 allows remote attackers to cause a denial of service (out-of-bounds read) via a relative URL containing a hostname, as demonstrated by a protocol-relative URL beginning with a //www.google.com/ substring.

    Published: 2 Oct 2013
    7.5
    High

    CVE-2013-2923

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 30.0.1599.66 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 2 Oct 2013
    7.5
    High

    CVE-2013-2912

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the PepperInProcessRouter::SendToHost function in content/renderer/pepper/pepper_in_process_router.cc in the Pepper Plug-in API (PPAPI) in Google Chrome before 30.0.1599.66 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a resource-destruction message.

    Published: 2 Oct 2013
    7.5
    High

    CVE-2013-2918

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the RenderBlock::collapseAnonymousBlockChild function in core/rendering/RenderBlock.cpp in the DOM implementation in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect handling of parent-child relationships for anonymous blocks.

    Published: 2 Oct 2013
    6.8
    Medium

    CVE-2013-2922

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in core/html/HTMLTemplateElement.cpp in Blink, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that operates on a TEMPLATE element.

    Published: 2 Oct 2013
    7.2
    High

    CVE-2013-4344

    Last Modified: 11 Apr 2025

    Buffer overflow in the SCSI implementation in QEMU, as used in Xen, when a SCSI controller has more than 256 attached devices, allows local users to gain privileges via a small transfer buffer in a REPORT LUNS command.

    Published: 2 Oct 2013
    4.3
    Medium

    CVE-2013-5975

    Last Modified: 11 Apr 2025

    The access policy logon page (logon.inc) in F5 BIG-IP APM 11.1.0 through 11.2.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors.

    Published: 1 Oct 2013
    4.3
    Medium

    CVE-2013-5976

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the access policy logout page (logout.inc) in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.1.0 through 11.3.0 allows remote attackers to inject arbitrary web script or HTML via the LastMRH_Session cookie.

    Published: 1 Oct 2013
    Unknown

    CVE-2013-4142

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3969. Reason: This candidate is a duplicate of CVE-2013-3969. Notes: All CVE users should reference CVE-2013-3969 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 1 Oct 2013