CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-5152

    Last Modified: 11 Apr 2025

    Mobile Safari in Apple iOS before 7 allows remote attackers to spoof the URL bar via a crafted web site.

    Published: 19 Sept 2013
    4.3
    Medium

    CVE-2013-5154

    Last Modified: 11 Apr 2025

    The Sandbox subsystem in Apple iOS before 7 determines the sandboxing requirement for a #! application on the basis of the script interpreter instead of the script, which allows attackers to bypass intended access restrictions via a crafted application.

    Published: 19 Sept 2013
    4.3
    Medium

    CVE-2013-5156

    Last Modified: 11 Apr 2025

    The Telephony subsystem in Apple iOS before 7 does not require API conformity for access to telephony-daemon interfaces, which allows attackers to bypass intended restrictions on phone calls via a crafted app that sends direct requests to the daemon.

    Published: 19 Sept 2013
    4.3
    Medium

    CVE-2013-5151

    Last Modified: 11 Apr 2025

    Mobile Safari in Apple iOS before 7 does not prevent HTML interpretation of a document served with a text/plain content type, which allows remote attackers to conduct cross-site scripting (XSS) attacks by uploading a file.

    Published: 19 Sept 2013
    6.1
    Medium

    CVE-2011-2391

    Last Modified: 11 Apr 2025

    The IPv6 implementation in the kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (CPU consumption) via crafted ICMPv6 packets.

    Published: 19 Sept 2013
    5.8
    Medium

    CVE-2013-0957

    Last Modified: 11 Apr 2025

    Data Protection in Apple iOS before 7 allows attackers to bypass intended limits on incorrect passcode entry, and consequently avoid a configured Erase Data setting, by leveraging the presence of an app in the third-party sandbox.

    Published: 19 Sept 2013
    4.3
    Medium

    CVE-2013-1034

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Wiki Server in Apple Mac OS X Server before 2.2.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Sept 2013
    9.3
    Critical

    CVE-2013-1035

    Last Modified: 11 Apr 2025

    The iTunes ActiveX control in Apple iTunes before 11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-1036

    Last Modified: 11 Apr 2025

    Safari in Apple iOS before 7 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted XML document.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-1039

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-1040

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-1041

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-1042

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-1043

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-1044

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-1047

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-5125

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-5126

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-5128

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    4.3
    Medium

    CVE-2013-5129

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in WebKit in Apple iOS before 7 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.

    Published: 19 Sept 2013
    4.3
    Medium

    CVE-2013-5131

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 19 Sept 2013
    Unknown

    CVE-2013-5134

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was assigned to an issue that is not within the scope of CVE. Notes: none

    Published: 19 Sept 2013
    4.7
    Medium

    CVE-2013-5138

    Last Modified: 11 Apr 2025

    IOCatalogue in IOKitUser in Apple iOS before 7 allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted application.

    Published: 19 Sept 2013
    9.3
    Critical

    CVE-2013-5139

    Last Modified: 11 Apr 2025

    The IOSerialFamily driver in Apple iOS before 7 allows attackers to execute arbitrary code or cause a denial of service (out-of-bounds array access) via a crafted application.

    Published: 19 Sept 2013
    7.8
    High

    CVE-2013-5140

    Last Modified: 11 Apr 2025

    The kernel in Apple iOS before 7 allows remote attackers to cause a denial of service (assertion failure and device restart) via an invalid packet fragment.

    Published: 19 Sept 2013
    4.9
    Medium

    CVE-2013-5142

    Last Modified: 11 Apr 2025

    The kernel in Apple iOS before 7 does not initialize unspecified kernel data structures, which allows local users to obtain sensitive information from kernel stack memory via the (1) msgctl API or (2) segctl API.

    Published: 19 Sept 2013
    6.3
    Medium

    CVE-2013-5145

    Last Modified: 11 Apr 2025

    kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) unload kernel extensions via a crafted message.

    Published: 19 Sept 2013
    3.7
    Low

    CVE-2013-5147

    Last Modified: 11 Apr 2025

    Passcode Lock in Apple iOS before 7 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging a race condition involving phone calls and ejection of a SIM card.

    Published: 19 Sept 2013
    4.3
    Medium

    CVE-2013-5149

    Last Modified: 11 Apr 2025

    The Push Notifications subsystem in Apple iOS before 7 provides the push-notification token to an app without user approval, which allows attackers to obtain sensitive information via an app that employs a crafted push-notification registration process.

    Published: 19 Sept 2013
    1.9
    Low

    CVE-2013-5150

    Last Modified: 11 Apr 2025

    The history-clearing feature in Safari in Apple iOS before 7 does not clear the back/forward history of an open tab, which allows physically proximate attackers to obtain sensitive information by leveraging an unattended workstation.

    Published: 19 Sept 2013
    2.1
    Low

    CVE-2013-5153

    Last Modified: 11 Apr 2025

    Springboard in Apple iOS before 7 does not properly manage the lock state in Lost Mode, which allows physically proximate attackers to read notifications via unspecified vectors.

    Published: 19 Sept 2013
    7.1
    High

    CVE-2013-5155

    Last Modified: 11 Apr 2025

    The Sandbox subsystem in Apple iOS before 7 allows attackers to cause a denial of service (infinite loop) via an application that writes crafted values to /dev/random.

    Published: 19 Sept 2013
    5
    Medium

    CVE-2013-5157

    Last Modified: 11 Apr 2025

    The Twitter subsystem in Apple iOS before 7 does not require API conformity for access to Twitter daemon interfaces, which allows attackers to post Tweets via a crafted app that sends direct requests to the daemon.

    Published: 19 Sept 2013
    2.1
    Low

    CVE-2013-5158

    Last Modified: 11 Apr 2025

    The Social subsystem in Apple iOS before 7 does not properly restrict access to the cache of Twitter icons, which allows physically proximate attackers to obtain sensitive information about recent Twitter interaction via unspecified vectors.

    Published: 19 Sept 2013
    4.3
    Medium

    CVE-2013-5159

    Last Modified: 11 Apr 2025

    WebKit in Apple iOS before 7 allows remote attackers to bypass the Same Origin Policy and obtain potentially sensitive information about use of the window.webkitRequestAnimationFrame API via an IFRAME element.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-1038

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    6.8
    Medium

    CVE-2013-1046

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 7, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-09-18-2.

    Published: 19 Sept 2013
    2.6
    Low

    CVE-2013-5137

    Last Modified: 11 Apr 2025

    IOKit in Apple iOS before 7 allows attackers to send user-interface events to the foreground app by leveraging control over a background app and using the (1) task-completion API or (2) VoIP API.

    Published: 19 Sept 2013
    7.1
    High

    CVE-2013-5141

    Last Modified: 11 Apr 2025

    The kernel in Apple iOS before 7 uses an incorrect data size for a certain integer variable, which allows attackers to cause a denial of service (infinite loop and device hang) via a crafted application, related to an "integer truncation vulnerability."

    Published: 19 Sept 2013
    2.1
    Low

    CVE-2013-4354

    Last Modified: 11 Apr 2025

    The API before 2.1 in OpenStack Image Registry and Delivery Service (Glance) makes it easier for local users to inject images into arbitrary tenants by adding the tenant as a member of the image.

    Published: 19 Sept 2013
    1.9
    Low

    CVE-2013-7336

    Last Modified: 12 Apr 2025

    The qemuMigrationWaitForSpice function in qemu/qemu_migration.c in libvirt before 1.1.3 does not properly enter a monitor when performing seamless SPICE migration, which allows local users to cause a denial of service (NULL pointer dereference and libvirtd crash) by causing domblkstat to be called at the same time as the qemuMonitorGetSpiceMigrationStatus function.

    Published: 19 Sept 2013
    8.8
    High

    CVE-2013-3893

    Last Modified: 22 Apr 2026

    Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.

    Published: 18 Sept 2013
    4
    Medium

    CVE-2013-1727

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.

    Published: 18 Sept 2013
    6.8
    Medium

    CVE-2013-1731

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in the GL tracing functionality in Mozilla Firefox before 24.0 on Android allows attackers to execute arbitrary code via a Trojan horse .so file in a world-writable directory.

    Published: 18 Sept 2013
    6.2
    Medium

    CVE-2013-1726

    Last Modified: 11 Apr 2025

    Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.

    Published: 18 Sept 2013
    7.2
    High

    CVE-2013-4288

    Last Modified: 11 Apr 2025

    Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new API function, (2) the dbus API, or (3) the --process (unix-process) option for authorization to pkcheck.

    Published: 18 Sept 2013
    4
    Medium

    CVE-2013-4296

    Last Modified: 11 Apr 2025

    The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via a crafted RPC call.

    Published: 18 Sept 2013
    4.6
    Medium

    CVE-2013-4311

    Last Modified: 11 Apr 2025

    libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

    Published: 18 Sept 2013
    4.6
    Medium

    CVE-2013-4324

    Last Modified: 11 Apr 2025

    spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

    Published: 18 Sept 2013
    4.6
    Medium

    CVE-2013-4326

    Last Modified: 11 Apr 2025

    RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.

    Published: 18 Sept 2013