CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2011-4396

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4400

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4401

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    6.2
    Medium

    CVE-2012-4096

    Last Modified: 11 Apr 2025

    The local file editor in the Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) allows local users to gain privileges and modify arbitrary fabric-interconnect files, in the context of a vi process, via unspecified commands, aka Bug ID CSCtn06574.

    Published: 1 Oct 2013
    7.5
    High

    CVE-2013-2924

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in International Components for Unicode (ICU), as used in Google Chrome before 30.0.1599.66 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 1 Oct 2013
    6.3
    Medium

    CVE-2013-5516

    Last Modified: 11 Apr 2025

    The Media Snapshot implementation on Cisco TelePresence Multipoint Switch (CTMS) devices allows remote authenticated users to cause a denial of service (device reload) by sending many Media Snapshot requests at the time of a meeting termination, aka Bug ID CSCuh44796.

    Published: 1 Oct 2013
    5
    Medium

    CVE-2013-5725

    Last Modified: 11 Apr 2025

    The Metaclassy Byword app 2.x before 2.1 for iOS does not require confirmation of Replace file actions, which allows remote attackers to overwrite arbitrary files via the name and text parameters in a byword://replace URL.

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4381

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4388

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4398

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    7.5
    High

    CVE-2013-2919

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 1 Oct 2013
    5.8
    Medium

    CVE-2013-4420

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the (1) tar_extract_glob and (2) tar_extract_all functions in libtar 1.2.20 and earlier allow remote attackers to overwrite arbitrary files via a .. (dot dot) in a crafted tar file.

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4380

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4383

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4384

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4386

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4387

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4390

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4391

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    Unknown

    CVE-2011-4397

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2011. Notes: none

    Published: 1 Oct 2013
    7.5
    High

    CVE-2013-5697

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.

    Published: 30 Sept 2013
    3.3
    Low

    CVE-2013-1444

    Last Modified: 11 Apr 2025

    A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222.

    Published: 30 Sept 2013
    7.2
    High

    CVE-2013-4362

    Last Modified: 11 Apr 2025

    WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) mount_davfs.c, related to the "system" function.

    Published: 30 Sept 2013
    4.3
    Medium

    CVE-2013-4623

    Last Modified: 11 Apr 2025

    The x509parse_crt function in x509.h in PolarSSL 1.1.x before 1.1.7 and 1.2.x before 1.2.8 does not properly parse certificate messages during the SSL/TLS handshake, which allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a certificate message that contains a PEM encoded certificate.

    Published: 30 Sept 2013
    6.8
    Medium

    CVE-2013-2238

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in the switch_perform_substitution function in switch_regex.c in FreeSWITCH 1.2 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to the index and substituted variables.

    Published: 30 Sept 2013
    8.5
    High

    CVE-2013-5692

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.

    Published: 30 Sept 2013
    4.3
    Medium

    CVE-2013-5693

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the model parameter to index.php/admin/editor.

    Published: 30 Sept 2013
    5
    Medium

    CVE-2013-4359

    Last Modified: 11 Apr 2025

    Integer overflow in kbdint.c in mod_sftp in ProFTPD 1.3.4d and 1.3.5r3 allows remote attackers to cause a denial of service (memory consumption) via a large response count value in an authentication request, which triggers a large memory allocation.

    Published: 30 Sept 2013
    2.1
    Low

    CVE-2013-5964

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the administration page in the Flag module 7.x-3.x before 7.x-3.1 for Drupal allows remote authenticated users with the "Administer flags" permission to inject arbitrary web script or HTML via the flag title.

    Published: 30 Sept 2013
    5
    Medium

    CVE-2013-5965

    Last Modified: 11 Apr 2025

    The Node View Permissions module 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the hook_query_alter function, which might allow remote attackers to obtain sensitive information by reading a node listing.

    Published: 30 Sept 2013
    4.3
    Medium

    CVE-2013-4378

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.

    Published: 30 Sept 2013
    5.1
    Medium

    CVE-2013-5962

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.

    Published: 30 Sept 2013
    6.8
    Medium

    CVE-2013-5963

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.

    Published: 30 Sept 2013
    6.8
    Medium

    CVE-2013-5961

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

    Published: 30 Sept 2013
    4.3
    Medium

    CVE-2013-5504

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Mobile Device Management (MDM) portal in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui30266.

    Published: 30 Sept 2013
    2.6
    Low

    CVE-2013-5679

    Last Modified: 11 Apr 2025

    The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against authenticity in the default configuration, involving a null MAC and a zero MAC length.

    Published: 30 Sept 2013
    5.8
    Medium

    CVE-2013-5960

    Last Modified: 11 Apr 2025

    The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0.1 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against the intended cipher mode in a non-default configuration, a different vulnerability than CVE-2013-5679.

    Published: 30 Sept 2013
    5
    Medium

    CVE-2013-3417

    Last Modified: 11 Apr 2025

    The administrative web interface in Cisco Video Surveillance Operations Manager does not properly perform authentication, which allows remote attackers to watch video feeds via a crafted URL, aka Bug ID CSCtg72262.

    Published: 30 Sept 2013
    4.3
    Medium

    CVE-2013-5505

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in an administration page in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui30275.

    Published: 30 Sept 2013
    5
    Medium

    CVE-2013-4210

    Last Modified: 11 Apr 2025

    The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors.

    Published: 30 Sept 2013
    1.5
    Low

    CVE-2013-4355

    Last Modified: 11 Apr 2025

    Xen 4.3.x and earlier does not properly handle certain errors, which allows local HVM guests to obtain hypervisor stack memory via a (1) port or (2) memory mapped I/O write or (3) other unspecified operations related to addresses without associated memory.

    Published: 30 Sept 2013
    2.1
    Low

    CVE-2013-4361

    Last Modified: 11 Apr 2025

    The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.

    Published: 30 Sept 2013
    6.8
    Medium

    CVE-2013-4330

    Last Modified: 11 Apr 2025

    Apache Camel before 2.9.7, 2.10.0 before 2.10.7, 2.11.0 before 2.11.2, and 2.12.0 allows remote attackers to execute arbitrary simple language expressions by including "$simple{}" in a CamelFileName message header to a (1) FILE or (2) FTP producer.

    Published: 30 Sept 2013
    5.4
    Medium

    CVE-2013-4356

    Last Modified: 11 Apr 2025

    Xen 4.3.x writes hypervisor mappings to certain shadow pagetables when live migration is performed on hosts with more than 5TB of RAM, which allows local 64-bit PV guests to read or write to invalid memory and cause a denial of service (crash).

    Published: 30 Sept 2013
    7.5
    High

    CVE-2013-4365

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.

    Published: 29 Sept 2013
    7.1
    High

    CVE-2013-5959

    Last Modified: 11 Apr 2025

    Blue Coat ProxySG before 6.2.14.1, 6.3.x, 6.4.x, and 6.5 before 6.5.2 allows remote attackers to cause a denial of service (memory consumption and dropped connections) via a recursive href in an HTML page, which triggers a large number of HTTP RW pipeline pre-fetch requests.

    Published: 28 Sept 2013
    6.8
    Medium

    CVE-2013-0598

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Web Client in IBM Rational ClearQuest 7.1 before 7.1.2.12, 8.0 before 8.0.0.8, and 8.0.1 before 8.0.1.1 allows remote attackers to hijack the authentication of arbitrary users.

    Published: 28 Sept 2013
    3.3
    Low

    CVE-2013-5160

    Last Modified: 11 Apr 2025

    Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by making a series of taps of the emergency-call button to trigger a NULL pointer dereference.

    Published: 28 Sept 2013
    4.4
    Medium

    CVE-2013-5161

    Last Modified: 11 Apr 2025

    Passcode Lock in Apple iOS before 7.0.2 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement, and open the Camera app or read the list of all recently opened apps, by leveraging unspecified transition errors.

    Published: 28 Sept 2013
    6.5
    Medium

    CVE-2012-1313

    Last Modified: 11 Apr 2025

    The remote debug shell on the PALO adapter card in Cisco Unified Computing System (UCS) allows local users to gain privileges via malformed show-macstats parameters, aka Bug ID CSCub13772.

    Published: 27 Sept 2013