CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2013-5498

    Last Modified: 11 Apr 2025

    The PPTP-ALG component in CRS Carrier Grade Services Engine (CGSE) and ASR 9000 Integrated Service Module (ISM) in Cisco IOS XR allows remote attackers to cause a denial of service (module reset) via crafted packet streams, aka Bug ID CSCue91963.

    Published: 27 Sept 2013
    10
    Critical

    CVE-2013-5403

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on the IBM WebSphere DataPower XC10 appliance 2.0 through 2.5.0.1 allows remote attackers to obtain administrative access via unknown vectors.

    Published: 27 Sept 2013
    6.8
    Medium

    CVE-2013-5093

    Last Modified: 11 Apr 2025

    The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.

    Published: 27 Sept 2013
    7.8
    High

    CVE-2013-5474

    Last Modified: 11 Apr 2025

    Race condition in the IPv6 virtual fragmentation reassembly (VFR) implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.3 allows remote attackers to cause a denial of service (device reload or hang) via fragmented IPv6 packets, aka Bug ID CSCud64812.

    Published: 27 Sept 2013
    6.8
    Medium

    CVE-2013-5942

    Last Modified: 11 Apr 2025

    Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object, related to (1) remote_storage.py, (2) storage.py, (3) render/datalib.py, and (4) whitelist/views.py, a different vulnerability than CVE-2013-5093.

    Published: 27 Sept 2013
    7.1
    High

    CVE-2013-5472

    Last Modified: 11 Apr 2025

    The NTP implementation in Cisco IOS 12.0 through 12.4 and 15.0 through 15.1, and IOS XE 2.1 through 3.3, does not properly handle encapsulation of multicast NTP packets within MSDP SA messages, which allows remote attackers to cause a denial of service (device reload) by leveraging an MSDP peer relationship, aka Bug ID CSCuc81226.

    Published: 27 Sept 2013
    7.8
    High

    CVE-2013-5473

    Last Modified: 11 Apr 2025

    Memory leak in Cisco IOS 12.2, 15.1, and 15.2; IOS XE 3.4.2S through 3.4.5S; and IOS XE 3.6.xS before 3.6.1S allows remote attackers to cause a denial of service (memory consumption or device reload) via malformed IKEv1 packets, aka Bug ID CSCtx66011.

    Published: 27 Sept 2013
    7.8
    High

    CVE-2013-5475

    Last Modified: 11 Apr 2025

    Cisco IOS 12.2 through 12.4 and 15.0 through 15.3, and IOS XE 2.1 through 3.9, allows remote attackers to cause a denial of service (device reload) via crafted DHCP packets that are processed locally by a (1) server or (2) relay agent, aka Bug ID CSCug31561.

    Published: 27 Sept 2013
    7.8
    High

    CVE-2013-5476

    Last Modified: 11 Apr 2025

    The Zone-Based Firewall (ZFW) feature in Cisco IOS 15.1 through 15.2, when content filtering or HTTP ALG inspection is enabled, allows remote attackers to cause a denial of service (device reload or hang) via crafted IPv4 HTTP traffic, aka Bug ID CSCtx56174.

    Published: 27 Sept 2013
    7.8
    High

    CVE-2013-5477

    Last Modified: 11 Apr 2025

    The T1/E1 driver-queue functionality in Cisco IOS 12.2 and 15.0 through 15.3, when an HDLC32 driver is used, allows remote attackers to cause a denial of service (interface queue wedge) via bursty network traffic, aka Bug ID CSCub67465.

    Published: 27 Sept 2013
    7.8
    High

    CVE-2013-5478

    Last Modified: 11 Apr 2025

    Cisco IOS 15.0 through 15.3 and IOS XE 3.2 through 3.8, when a VRF interface exists, allows remote attackers to cause a denial of service (interface queue wedge) via crafted UDP RSVP packets, aka Bug ID CSCuf17023.

    Published: 27 Sept 2013
    7.8
    High

    CVE-2013-5479

    Last Modified: 11 Apr 2025

    The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka Bug ID CSCtn53730.

    Published: 27 Sept 2013
    7.8
    High

    CVE-2013-5480

    Last Modified: 11 Apr 2025

    The DNS-over-TCP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via a crafted IPv4 DNS TCP stream, aka Bug ID CSCuf28733.

    Published: 27 Sept 2013
    7.1
    High

    CVE-2013-5481

    Last Modified: 11 Apr 2025

    The PPTP implementation in Cisco IOS 12.2 and 15.0 through 15.3, when NAT is used, allows remote attackers to cause a denial of service (device reload) via crafted TCP port-1723 packets, aka Bug ID CSCtq14817.

    Published: 27 Sept 2013
    4.3
    Medium

    CVE-2013-5943

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Graphite before 0.9.11 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Sept 2013
    4.3
    Medium

    CVE-2013-4399

    Last Modified: 12 Apr 2025

    The remoteClientFreeFunc function in daemon/remote.c in libvirt before 1.1.3, when ACLs are used, does not set an identity, which causes event handler removal to be denied and remote attackers to cause a denial of service (use-after-free and crash) by registering an event handler and then closing the connection.

    Published: 27 Sept 2013
    4.3
    Medium

    CVE-2013-4626

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the BackWPup plugin before 3.0.13 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter to wp-admin/admin.php.

    Published: 26 Sept 2013
    5
    Medium

    CVE-2012-4079

    Last Modified: 11 Apr 2025

    The XML API service in the Fabric Interconnect component in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service (API service outage) via a malformed XML document in a packet, aka Bug ID CSCtg48206.

    Published: 26 Sept 2013
    4.3
    Medium

    CVE-2012-4088

    Last Modified: 11 Apr 2025

    The FTP server in Cisco Unified Computing System (UCS) has a hardcoded password for an unspecified user account, which makes it easier for remote attackers to read or modify files by leveraging knowledge of this password, aka Bug ID CSCtg20769.

    Published: 26 Sept 2013
    Unknown

    CVE-2013-2026

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4971. Reason: This candidate is a reservation duplicate of CVE-2011-4971. Notes: All CVE users should reference CVE-2011-4971 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Sept 2013
    Unknown

    CVE-2013-2229

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2218. Reason: This candidate is a reservation duplicate of CVE-2013-2218. Notes: All CVE users should reference CVE-2013-2218 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 26 Sept 2013
    Unknown

    CVE-2013-5575

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 26 Sept 2013
    5.8
    Medium

    CVE-2012-4092

    Last Modified: 11 Apr 2025

    The management interface in the Central Software component in Cisco Unified Computing System (UCS) does not properly validate the identity of vCenter consoles, which allows man-in-the-middle attackers to read or modify an inter-device data stream by spoofing an identity, aka Bug ID CSCtk00683.

    Published: 26 Sept 2013
    4.3
    Medium

    CVE-2013-5586

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wikka.php in WikkaWiki before 1.3.4-p1 allows remote attackers to inject arbitrary web script or HTML via the wakka parameter to sql/.

    Published: 25 Sept 2013
    6.8
    Medium

    CVE-2013-5937

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to hijack the authentication of administrators for requests that delete database information via vectors involving the Drupal Form API.

    Published: 25 Sept 2013
    4.3
    Medium

    CVE-2013-5938

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Click2Sell Suite module 6.x-1.x for Drupal allows remote attackers to inject arbitrary web script or HTML via a confirmation form.

    Published: 25 Sept 2013
    6.9
    Medium

    CVE-2013-1060

    Last Modified: 11 Apr 2025

    A certain Ubuntu build procedure for perf, as distributed in the Linux kernel packages in Ubuntu 10.04 LTS, 12.04 LTS, 12.10, 13.04, and 13.10, sets the HOME environment variable to the ~buildd directory and consequently reads the system configuration file from the ~buildd directory, which allows local users to gain privileges by leveraging control over the buildd account.

    Published: 25 Sept 2013
    4.3
    Medium

    CVE-2013-4024

    Last Modified: 11 Apr 2025

    IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x support HTTP access to the Web Console, which allows remote attackers to read session cookies by sniffing the network.

    Published: 25 Sept 2013
    6.9
    Medium

    CVE-2013-4777

    Last Modified: 11 Apr 2025

    A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that listens for shell commands, which allows local users to gain privileges by interacting with a LocalSocket object.

    Published: 25 Sept 2013
    4.3
    Medium

    CVE-2013-5118

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail message.

    Published: 25 Sept 2013
    7.5
    High

    CVE-2013-5200

    Last Modified: 11 Apr 2025

    The (1) REST and (2) memcache interfaces in the Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 do not require authentication, which allows remote attackers to obtain sensitive information or modify data via an API call.

    Published: 25 Sept 2013
    6.9
    Medium

    CVE-2013-5373

    Last Modified: 11 Apr 2025

    The RemoteClient component in IBM Rational ClearCase 8.0.0.03 through 8.0.0.07, and 8.0.1, uses world-writable permissions for the rcleartool script, which allows local users to gain privileges by appending commands.

    Published: 25 Sept 2013
    6.9
    Medium

    CVE-2013-5933

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless allows local users to gain privileges or cause a denial of service (memory corruption) by writing a long string to the /dev/socket/init_runit socket that is inconsistent with a certain length value that was previously written to this socket.

    Published: 25 Sept 2013
    4
    Medium

    CVE-2013-5934

    Last Modified: 11 Apr 2025

    Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 has a hardcoded password for node join operations, which allows remote attackers to expand a cluster by finding this password in the source code and then sending the password in a Hazelcast cluster API call, a different vulnerability than CVE-2013-5200.

    Published: 25 Sept 2013
    4.3
    Medium

    CVE-2013-5935

    Last Modified: 11 Apr 2025

    The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 does not properly restrict the set of network interfaces that can receive API calls, which makes it easier for remote attackers to obtain access by sending network traffic from an unintended location, a different vulnerability than CVE-2013-5200.

    Published: 25 Sept 2013
    4.3
    Medium

    CVE-2013-5936

    Last Modified: 11 Apr 2025

    The Hazelcast cluster API in Open-Xchange AppSuite 7.0.x before 7.0.2-rev15 and 7.2.x before 7.2.2-rev16 allows remote attackers to obtain sensitive information about (1) runtime activity, (2) network configuration, (3) user sessions, (4) the memcache interface, and (5) the REST interface via API calls such as a hazelcast/rest/cluster/ call, a different vulnerability than CVE-2013-5200.

    Published: 25 Sept 2013
    5.1
    Medium

    CVE-2012-4086

    Last Modified: 11 Apr 2025

    A setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20790.

    Published: 25 Sept 2013
    3.5
    Low

    CVE-2013-4022

    Last Modified: 11 Apr 2025

    IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x store unspecified authentication information in a cookie, which allows remote authenticated users to bypass intended access restrictions via unknown vectors.

    Published: 25 Sept 2013
    1.9
    Low

    CVE-2013-4025

    Last Modified: 11 Apr 2025

    IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

    Published: 25 Sept 2013
    4.3
    Medium

    CVE-2013-5634

    Last Modified: 11 Apr 2025

    arch/arm/kvm/arm.c in the Linux kernel before 3.10 on the ARM platform, when KVM is used, allows host OS users to cause a denial of service (NULL pointer dereference, OOPS, and host OS crash) or possibly have unspecified other impact by omitting vCPU initialization before a KVM_GET_REG_LIST ioctl call.

    Published: 25 Sept 2013
    5
    Medium

    CVE-2013-5750

    Last Modified: 11 Apr 2025

    The login form in the FriendsOfSymfony FOSUserBundle bundle before 1.3.3 for Symfony allows remote attackers to cause a denial of service (CPU consumption) via a long password that triggers an expensive hash computation, as demonstrated by a PBKDF2 computation.

    Published: 25 Sept 2013
    4.3
    Medium

    CVE-2013-5911

    Last Modified: 17 Aug 2026

    Cross-site scripting (XSS) vulnerability in devform.php in Tenable SecurityCenter 4.6 through 4.7 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

    Published: 24 Sept 2013
    4.3
    Medium

    CVE-2013-3589

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46.45 allows remote attackers to inject arbitrary web script or HTML via the ErrorMsg parameter.

    Published: 24 Sept 2013
    Unknown

    CVE-2013-3611

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 24 Sept 2013
    5.1
    Medium

    CVE-2012-4087

    Last Modified: 11 Apr 2025

    A cluster setup script for fabric interconnect devices in Cisco Unified Computing System (UCS) allows remote attackers to execute arbitrary commands via invalid parameters, aka Bug ID CSCtg20793.

    Published: 24 Sept 2013
    4.3
    Medium

    CVE-2013-3616

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the KnowledgeView Editorial and Management application allows remote attackers to inject arbitrary web script or HTML via the username parameter.

    Published: 24 Sept 2013
    3.5
    Low

    CVE-2013-5221

    Last Modified: 11 Apr 2025

    The mobile-upload feature in Esri ArcGIS for Server 10.1 through 10.2 allows remote authenticated users to upload .exe files by leveraging (1) publisher or (2) administrator privileges.

    Published: 24 Sept 2013
    8.5
    High

    CVE-2012-4078

    Last Modified: 11 Apr 2025

    The Baseboard Management Controller (BMC) in Cisco Unified Computing System (UCS) does not properly handle SSH escape sequences, which allows remote authenticated users to bypass an unspecified authentication step via SSH port forwarding, aka Bug ID CSCtg17656.

    Published: 24 Sept 2013
    6.6
    Medium

    CVE-2012-4089

    Last Modified: 11 Apr 2025

    MCTOOLS in the fabric interconnect in Cisco Unified Computing System (UCS) allows local users to execute arbitrary Baseboard Management Controller (BMC) commands by leveraging (1) local, (2) shell-level, or (3) debug-level privileges at the operating-system layer, aka Bug ID CSCtg76239.

    Published: 24 Sept 2013
    5.4
    Medium

    CVE-2012-4094

    Last Modified: 11 Apr 2025

    Buffer overflow in the Smart Call Home feature in the fabric interconnect in Cisco Unified Computing System (UCS) allows remote attackers to cause a denial of service by reading and forging control messages associated with Smart Call Home reports, aka Bug ID CSCtl00198.

    Published: 24 Sept 2013