CVE Feed

    Dashboard / CVE

    7.1
    High

    CVE-2013-3688

    Last Modified: 11 Apr 2025

    The TP-Link IP Cameras TL-SC3171, TL-SC3130, TL-SC3130G, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, does not properly restrict access to certain administrative functions, which allows remote attackers to (1) cause a denial of service (device reboot) via a request to cgi-bin/reboot or (2) cause a denial of service (reboot and reset to factory defaults) via a request to cgi-bin/hardfactorydefault.

    Published: 1 Oct 2013
    6.8
    Medium

    CVE-2013-3690

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 and earlier, allows remote attackers to hijack the authentication of administrators for requests that add users.

    Published: 1 Oct 2013
    6.8
    Medium

    CVE-2013-3963

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models allows remote attackers to hijack the authentication of unspecified victims for requests that add users.

    Published: 1 Oct 2013
    4.3
    Medium

    CVE-2013-3964

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Samsung SHR-5162, SHR-5082, and possibly other models, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 1 Oct 2013
    6.8
    Medium

    CVE-2013-3539

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.

    Published: 1 Oct 2013
    4.3
    Medium

    CVE-2013-3962

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models before firmware 1.0.4.44, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 1 Oct 2013
    4.3
    Medium

    CVE-2013-5580

    Last Modified: 11 Apr 2025

    The (1) Conn_StartLogin and (2) cb_Read_Resolver_Result functions in conn.c in ngIRCd 18 through 20.2, when the configuration option NoticeAuth is enabled, does not properly handle the return code for the Handle_Write function, which allows remote attackers to cause a denial of service (assertion failure and server crash) via unspecified vectors, related to a "notice auth" message not being sent to a new client.

    Published: 1 Oct 2013
    5
    Medium

    CVE-2013-2269

    Last Modified: 11 Apr 2025

    The Sponsorship Confirmation functionality in Aruba Networks ClearPass 5.x, 6.0.1, and 6.0.2, and Amigopod/ClearPass Guest 3.0 through 3.9.7, allows remote attackers to bypass intended access restrictions and approve a request by sending a guest request, then using "parameter manipulation" in conjunction with information from a "default holding page" to discover the link that is used for sponsor approval of the guest request, then performing a direct request to that link.

    Published: 1 Oct 2013
    4
    Medium

    CVE-2013-4708

    Last Modified: 11 Apr 2025

    The PPP Access Concentrator (PPPAC) in Internet Initiative Japan Inc. SEIL/x86 1.00 through 2.80, SEIL/X1 1.00 through 4.30, SEIL/X2 1.00 through 4.30, SEIL/B1 1.00 through 4.30, SEIL/Turbo 1.80 through 2.15, and SEIL/neu 2FE Plus 1.80 through 2.15 generates predictable random numbers, which allows remote attackers to bypass RADIUS authentication by sniffing RADIUS traffic.

    Published: 1 Oct 2013
    3.5
    Low

    CVE-2013-3048

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Oct 2013
    4
    Medium

    CVE-2013-3971

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3049.

    Published: 1 Oct 2013
    4
    Medium

    CVE-2013-3972

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 1 Oct 2013
    5
    Medium

    CVE-2013-4013

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.2 allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 1 Oct 2013
    4.3
    Medium

    CVE-2013-4014

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Oct 2013
    6.5
    Medium

    CVE-2013-4017

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 1 Oct 2013
    6
    Medium

    CVE-2013-4018

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to obtain sensitive information via unspecified vectors.

    Published: 1 Oct 2013
    4
    Medium

    CVE-2013-4020

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

    Published: 1 Oct 2013
    6.5
    Medium

    CVE-2013-4021

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to conduct unspecified file-inclusion attacks via unknown vectors.

    Published: 1 Oct 2013
    6.5
    Medium

    CVE-2013-4027

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors.

    Published: 1 Oct 2013
    6.5
    Medium

    CVE-2013-5381

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 through 7.1.1.12, and 7.5 before 7.5.0.3 allows remote authenticated users to gain privileges via unspecified vectors.

    Published: 1 Oct 2013
    6.8
    Medium

    CVE-2012-3323

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 before 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.3 allows remote attackers to gain privileges via unspecified vectors.

    Published: 1 Oct 2013
    6.5
    Medium

    CVE-2013-0451

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 through 7.1.1.12 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 1 Oct 2013
    6.5
    Medium

    CVE-2013-3047

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors.

    Published: 1 Oct 2013
    2.1
    Low

    CVE-2013-5380

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows local users to obtain sensitive information via unspecified vectors.

    Published: 1 Oct 2013
    4
    Medium

    CVE-2013-5383

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5382.

    Published: 1 Oct 2013
    7.5
    High

    CVE-2013-5395

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 1 Oct 2013
    4
    Medium

    CVE-2013-3049

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 7.1 through 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to bypass intended access restrictions via unspecified vectors, a different vulnerability than CVE-2013-3971.

    Published: 1 Oct 2013
    6.5
    Medium

    CVE-2013-3973

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in IBM Maximo Asset Management 7.1 before 7.1.1.12 and 7.5 before 7.5.0.5 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Published: 1 Oct 2013
    3.5
    Low

    CVE-2013-4019

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 6.2.8 and 7.1 before 7.1.1.12 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 1 Oct 2013
    4
    Medium

    CVE-2013-5382

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote authenticated users to gain privileges via unspecified vectors, a different vulnerability than CVE-2013-5383.

    Published: 1 Oct 2013
    10
    Critical

    CVE-2013-5370

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-4042.

    Published: 1 Oct 2013
    4.9
    Medium

    CVE-2013-3278

    Last Modified: 11 Apr 2025

    EMC VPLEX before VPLEX GeoSynchrony 5.2 SP1 uses cleartext for storage of the LDAP/AD bind password, which allows local users to obtain sensitive information by reading the management-server configuration file.

    Published: 1 Oct 2013
    3.5
    Low

    CVE-2013-5572

    Last Modified: 11 Apr 2025

    Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.

    Published: 1 Oct 2013
    10
    Critical

    CVE-2013-4042

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM SPSS Collaboration and Deployment Services 4.2.1 and 5.0 through FP2 allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-5370.

    Published: 1 Oct 2013
    4.3
    Medium

    CVE-2013-3041

    Last Modified: 11 Apr 2025

    The Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to obtain sensitive information from the client-server data stream via unspecified vectors associated with a "JSON hijacking attack."

    Published: 1 Oct 2013
    5
    Medium

    CVE-2013-4284

    Last Modified: 11 Apr 2025

    Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax update request.

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4399

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4402

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4375

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4376

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4377

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4378

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4379

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4382

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4385

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4389

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4392

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4393

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4394

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4395

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013