CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-4047

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote attackers to inject arbitrary web script or HTML via a crafted link.

    Published: 16 Sept 2013
    3.5
    Low

    CVE-2013-4048

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving addition of script to a page.

    Published: 16 Sept 2013
    9.3
    Critical

    CVE-2013-5369

    Last Modified: 11 Apr 2025

    IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 might allow remote attackers to execute arbitrary code by deploying and accessing a service.

    Published: 16 Sept 2013
    8.5
    High

    CVE-2013-4049

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in IBM SPSS Analytical Decision Management 6.1 before IF1, 6.2 before IF1, and 7.0 before FP1 IF6 allows remote authenticated users to execute arbitrary code by uploading and accessing a JSP file.

    Published: 16 Sept 2013
    7.5
    High

    CVE-2013-4313

    Last Modified: 11 Apr 2025

    Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.

    Published: 16 Sept 2013
    4.3
    Medium

    CVE-2013-4341

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

    Published: 16 Sept 2013
    7.5
    High

    CVE-2013-5674

    Last Modified: 11 Apr 2025

    badges/external.php in Moodle 2.5.x before 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote attackers to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

    Published: 16 Sept 2013
    5.8
    Medium

    CVE-2012-6087

    Last Modified: 11 Apr 2025

    repository/s3/S3.php in the Amazon S3 library in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to an incorrect CURLOPT_SSL_VERIFYHOST value.

    Published: 16 Sept 2013
    5.8
    Medium

    CVE-2013-1028

    Last Modified: 11 Apr 2025

    The IPSec implementation in Apple Mac OS X before 10.8.5, when Hybrid Auth is used, does not verify X.509 certificates from security gateways, which allows man-in-the-middle attackers to spoof security gateways and obtain sensitive information via a crafted certificate.

    Published: 16 Sept 2013
    4.3
    Medium

    CVE-2013-1824

    Last Modified: 11 Apr 2025

    The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue in the soap_xmlParseFile and soap_xmlParseMemory functions.

    Published: 16 Sept 2013
    6.3
    Medium

    CVE-2013-5496

    Last Modified: 11 Apr 2025

    Open Network Environment Platform (ONEP) in Cisco NX-OS allows remote authenticated users to cause a denial of service (network-element reload) via a crafted packet, aka Bug ID CSCui51551.

    Published: 16 Sept 2013
    6.8
    Medium

    CVE-2013-5494

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Unified MeetingPlace Solution, as used in Unified MeetingPlace Web Conferencing and Unified MeetingPlace, allows remote attackers to hijack the authentication of arbitrary users, aka Bug IDs CSCui45209 and CSCui44674.

    Published: 16 Sept 2013
    4.9
    Medium

    CVE-2013-1029

    Last Modified: 11 Apr 2025

    The kernel in Apple Mac OS X before 10.8.5 allows remote attackers to cause a denial of service (panic) via crafted IGMP packets that leverage incorrect, extraneous code in the IGMP parser.

    Published: 16 Sept 2013
    6.8
    Medium

    CVE-2013-1025

    Last Modified: 11 Apr 2025

    Buffer overflow in CoreGraphics in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JBIG2 data in a PDF document.

    Published: 16 Sept 2013
    6.8
    Medium

    CVE-2013-1026

    Last Modified: 11 Apr 2025

    Buffer overflow in ImageIO in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG2000 data in a PDF document.

    Published: 16 Sept 2013
    6.8
    Medium

    CVE-2013-1027

    Last Modified: 11 Apr 2025

    Installer in Apple Mac OS X before 10.8.5 provides an option to continue a package's installation after encountering a revoked certificate, which might allow user-assisted remote attackers to execute arbitrary code via a crafted package.

    Published: 16 Sept 2013
    2.1
    Low

    CVE-2013-1030

    Last Modified: 11 Apr 2025

    mdmclient in Mobile Device Management in Apple Mac OS X before 10.8.5 places a password on the command line, which allows local users to obtain sensitive information by listing the process.

    Published: 16 Sept 2013
    3.3
    Low

    CVE-2013-1031

    Last Modified: 11 Apr 2025

    Power Management in Apple Mac OS X before 10.8.5 does not properly perform locking upon occurrences of a power assertion, which allows physically proximate attackers to bypass intended access restrictions by visiting an unattended workstation on which a locking failure had prevented the startup of the screen saver.

    Published: 16 Sept 2013
    6.8
    Medium

    CVE-2013-1032

    Last Modified: 11 Apr 2025

    QuickTime in Apple Mac OS X before 10.8.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted idsc atom in a QuickTime movie file.

    Published: 16 Sept 2013
    5.5
    Medium

    CVE-2013-1033

    Last Modified: 11 Apr 2025

    Screen Lock in Apple Mac OS X before 10.8.5 does not properly track sessions, which allows remote authenticated users to bypass locking by leveraging screen-sharing access.

    Published: 16 Sept 2013
    4.3
    Medium

    CVE-2013-4704

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in ChamaNet ChamaCargo 7.0000 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Sept 2013
    4.3
    Medium

    CVE-2013-5495

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web framework in the Application Server in Cisco Unified MeetingPlace allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCui44681.

    Published: 16 Sept 2013
    6.8
    Medium

    CVE-2013-4349

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4540. Reason: This candidate was MERGED into CVE-2012-4540, since it was later discovered that it affected an additional version, but it does not constitute a regression error. Notes: All CVE users should reference CVE-2012-4540 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 16 Sept 2013
    4.3
    Medium

    CVE-2013-4363

    Last Modified: 11 Apr 2025

    Algorithmic complexity vulnerability in Gem::Version::ANCHORED_VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.2, 1.8.24 through 1.8.26, 2.0.x before 2.0.10, and 2.1.x before 2.1.5, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression. NOTE: this issue is due to an incomplete fix for CVE-2013-4287.

    Published: 15 Sept 2013
    5
    Medium

    CVE-2013-1443

    Last Modified: 11 Apr 2025

    The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption) via a long password which is then hashed.

    Published: 15 Sept 2013
    7.5
    High

    CVE-2013-4809

    Last Modified: 22 Apr 2025

    Multiple SQL injection vulnerabilities in GetEventsServlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allow remote attackers to execute arbitrary SQL commands via the (1) sort or (2) dir parameter.

    Published: 13 Sept 2013
    10
    Critical

    CVE-2013-4812

    Last Modified: 22 Apr 2025

    UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

    Published: 13 Sept 2013
    10
    Critical

    CVE-2013-4813

    Last Modified: 22 Apr 2025

    The Agent (aka AgentController) servlet in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 allows remote attackers to execute arbitrary commands via a HEAD request, aka ZDI-CAN-1745.

    Published: 13 Sept 2013
    10
    Critical

    CVE-2013-4811

    Last Modified: 22 Apr 2025

    UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

    Published: 13 Sept 2013
    4.3
    Medium

    CVE-2013-5482

    Last Modified: 11 Apr 2025

    Cisco Prime LAN Management Solution (LMS) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)" issue, aka Bug ID CSCug77823.

    Published: 13 Sept 2013
    5
    Medium

    CVE-2013-5489

    Last Modified: 11 Apr 2025

    The gadget implementation in Cisco SocialMiner does not properly restrict the content of GET requests, which allows remote attackers to obtain sensitive information by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history, aka Bug ID CSCuh74125.

    Published: 13 Sept 2013
    4.3
    Medium

    CVE-2013-5649

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.1 before 7.1r15, 7.2 before 7.2r11, 7.3 before 7.3r6, and 7.4 before 7.4r3 allow (1) remote attackers to inject arbitrary web script or HTML via vectors involving login pages, and allow (2) remote authenticated users to inject arbitrary web script or HTML via vectors involving a support page.

    Published: 13 Sept 2013
    6.8
    Medium

    CVE-2013-5493

    Last Modified: 11 Apr 2025

    The diagnostic module in the firmware on Cisco Virtualization Experience Client 6000 devices allows local users to bypass intended access restrictions and execute arbitrary commands via unspecified vectors, aka Bug ID CSCug68407.

    Published: 13 Sept 2013
    4.3
    Medium

    CVE-2013-4705

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Opera before 15.00 allows remote attackers to inject arbitrary web script or HTML by leveraging UTF-8 encoding.

    Published: 13 Sept 2013
    5
    Medium

    CVE-2013-5492

    Last Modified: 11 Apr 2025

    administration.jsp in Cisco SocialMiner allows remote attackers to obtain sensitive information by sniffing the network for HTTP client-server traffic, aka Bug ID CSCuh76780.

    Published: 13 Sept 2013
    10
    Critical

    CVE-2013-2933

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

    Published: 12 Sept 2013
    10
    Critical

    CVE-2013-2938

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

    Published: 12 Sept 2013
    5
    Medium

    CVE-2013-5216

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in logreader/uploadreader.jsp in CapaSystems Performance Guard before 6.2.102 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 12 Sept 2013
    7.5
    High

    CVE-2013-2601

    Last Modified: 11 Apr 2025

    The NDVM in Citrix XenClient XT before 2.1.3 and 3.x before 3.1.4 allows remote attackers to execute arbitrary commands by using the UIVM to create a network connection.

    Published: 12 Sept 2013
    10
    Critical

    CVE-2013-2935

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

    Published: 12 Sept 2013
    10
    Critical

    CVE-2013-2936

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

    Published: 12 Sept 2013
    10
    Critical

    CVE-2013-2940

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

    Published: 12 Sept 2013
    10
    Critical

    CVE-2013-2934

    Last Modified: 11 Apr 2025

    Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 does not properly restrict access to web services, which has unspecified impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

    Published: 12 Sept 2013
    10
    Critical

    CVE-2013-2937

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, related to debugging messages, a different vulnerability than other CVEs listed in CTX137162.

    Published: 12 Sept 2013
    10
    Critical

    CVE-2013-2939

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.

    Published: 12 Sept 2013
    6.9
    Medium

    CVE-2013-5740

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Intel Trusted Execution Technology (TXT) SINIT Authenticated Code Modules (ACM) before 1.2, as used by the Intel QM77, QS77, Q77 Express, C216, Q67 Express, C202, C204, and C206 chipsets and Mobile Intel QM67 and QS67 chipsets, when the measured launch environment (MLE) is invoked, allows local users to bypass the Trusted Execution Technology protection mechanism and perform other unspecified SINIT ACM functions via unspecified vectors.

    Published: 12 Sept 2013
    7.5
    High

    CVE-2013-4339

    Last Modified: 11 Apr 2025

    WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.

    Published: 12 Sept 2013
    4.3
    Medium

    CVE-2013-5738

    Last Modified: 11 Apr 2025

    The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file.

    Published: 12 Sept 2013
    7.5
    High

    CVE-2013-4338

    Last Modified: 11 Apr 2025

    wp-includes/functions.php in WordPress before 3.6.1 does not properly determine whether data has been serialized, which allows remote attackers to execute arbitrary code by triggering erroneous PHP unserialize operations.

    Published: 12 Sept 2013
    3.5
    Low

    CVE-2013-4340

    Last Modified: 11 Apr 2025

    wp-admin/includes/post.php in WordPress before 3.6.1 allows remote authenticated users to spoof the authorship of a post by leveraging the Author role and providing a modified user_ID parameter.

    Published: 12 Sept 2013