CVE Feed

    Dashboard / CVE

    3.5
    Low

    CVE-2013-5739

    Last Modified: 11 Apr 2025

    The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) attacks via a crafted file, related to the get_allowed_mime_types function in wp-includes/functions.php.

    Published: 12 Sept 2013
    4.4
    Medium

    CVE-2013-3037

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for local users to gain privileges via unknown vectors.

    Published: 12 Sept 2013
    5
    Medium

    CVE-2013-5488

    Last Modified: 11 Apr 2025

    Cisco Common Services, as used in Cisco Prime LAN Management Solution (LMS), Cisco Security Manager, Cisco Unified Service Monitor, and Cisco Unified Operations Manager, does not properly interact with the ActiveMQ component, which allows remote attackers to cause a denial of service (memory consumption) via simultaneous TCP sessions, aka Bug IDs CSCuh54766, CSCuh01267, CSCuh95976, and CSCuh95969.

    Published: 12 Sept 2013
    4.9
    Medium

    CVE-2013-3036

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in IBM Rational Requirements Composer before 4.0.4 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL.

    Published: 12 Sept 2013
    5.4
    Medium

    CVE-2013-3039

    Last Modified: 11 Apr 2025

    IBM Rational Requirements Composer before 4.0.4 does not properly perform authentication, which has unspecified impact and remote attack vectors.

    Published: 12 Sept 2013
    5.8
    Medium

    CVE-2013-3446

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the login page in Cisco Digital Media Manager (DMM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCub23849.

    Published: 12 Sept 2013
    5.4
    Medium

    CVE-2013-3038

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM Rational Requirements Composer before 4.0.4 makes it easier for remote attackers to discover credentials via unknown vectors.

    Published: 12 Sept 2013
    5
    Medium

    CVE-2013-7423

    Last Modified: 12 Apr 2025

    The send_dg function in resolv/res_send.c in GNU C Library (aka glibc or libc6) before 2.20 does not properly reuse file descriptors, which allows remote attackers to send DNS queries to unintended locations via a large number of requests that trigger a call to the getaddrinfo function.

    Published: 12 Sept 2013
    10
    Critical

    CVE-2013-3351

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allow attackers to execute arbitrary code via unspecified vectors.

    Published: 11 Sept 2013
    10
    Critical

    CVE-2013-3352

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3354 and CVE-2013-3355.

    Published: 11 Sept 2013
    10
    Critical

    CVE-2013-3353

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3356.

    Published: 11 Sept 2013
    10
    Critical

    CVE-2013-3354

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3352 and CVE-2013-3355.

    Published: 11 Sept 2013
    10
    Critical

    CVE-2013-3357

    Last Modified: 11 Apr 2025

    Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3358.

    Published: 11 Sept 2013
    10
    Critical

    CVE-2013-3358

    Last Modified: 11 Apr 2025

    Integer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3357.

    Published: 11 Sept 2013
    10
    Critical

    CVE-2013-3359

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3360.

    Published: 11 Sept 2013
    10
    Critical

    CVE-2013-3360

    Last Modified: 11 Apr 2025

    Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3359.

    Published: 11 Sept 2013
    10
    Critical

    CVE-2013-3355

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3352 and CVE-2013-3354.

    Published: 11 Sept 2013
    10
    Critical

    CVE-2013-3356

    Last Modified: 11 Apr 2025

    Buffer overflow in Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-3353.

    Published: 11 Sept 2013
    4.3
    Medium

    CVE-2013-4307

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in repo/includes/EntityView.php in the Wikibase extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow (1) remote attackers to inject arbitrary web script or HTML via a label in the "In other languages" section or (2) remote administrators to inject arbitrary web script or HTML via a description.

    Published: 11 Sept 2013
    4.3
    Medium

    CVE-2013-4308

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in pages/TalkpageHistoryView.php in the LiquidThreads (LQT) extension 2.x and possibly 3.x for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allows remote attackers to inject arbitrary web script or HTML via a thread subject.

    Published: 11 Sept 2013
    2.1
    Low

    CVE-2013-5724

    Last Modified: 11 Apr 2025

    Phpbb3 before 3.0.11-4 for Debian GNU/Linux uses world-writable permissions for cache files, which allows local users to modify the file contents via standard filesystem write operations.

    Published: 11 Sept 2013
    7.5
    High

    CVE-2013-5723

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD0_DELETE_DERIVATION_TABLE."

    Published: 11 Sept 2013
    10
    Critical

    CVE-2013-1330

    Last Modified: 11 Apr 2025

    The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 does not set the EnableViewStateMac attribute, which allows remote attackers to execute arbitrary code by leveraging an unassigned workflow, aka "MAC Disabled Vulnerability."

    Published: 11 Sept 2013
    4.3
    Medium

    CVE-2013-3159

    Last Modified: 11 Apr 2025

    Microsoft Excel 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Excel Viewer; and Microsoft Office Compatibility Pack SP3 allow remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka "XML External Entities Resolution Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3207

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3201, CVE-2013-3203, CVE-2013-3206, and CVE-2013-3209.

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3845

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3848

    Last Modified: 11 Apr 2025

    Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3849, and CVE-2013-3858.

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3849

    Last Modified: 11 Apr 2025

    Microsoft Word Automation Services in SharePoint Server 2010 SP1, Word Web App 2010 SP1 in Office Web Apps 2010, Word 2003 SP3, Word 2007 SP3, Word 2010 SP1, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3847, CVE-2013-3848, and CVE-2013-3858.

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3851

    Last Modified: 11 Apr 2025

    Microsoft Office 2003 SP3 and 2007 SP3, Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3852

    Last Modified: 11 Apr 2025

    Microsoft Word 2003 SP3, 2007 SP3, and 2010 SP1; Office Compatibility Pack SP3; and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3853

    Last Modified: 11 Apr 2025

    Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3854.

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3854

    Last Modified: 11 Apr 2025

    Microsoft Office 2007 SP3 and Word 2007 SP3 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3853.

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3855

    Last Modified: 11 Apr 2025

    Microsoft Word 2003 SP3 and 2007 SP3, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3856

    Last Modified: 11 Apr 2025

    Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."

    Published: 11 Sept 2013
    6.9
    Medium

    CVE-2013-3859

    Last Modified: 11 Apr 2025

    Microsoft Pinyin IME 2010, when used in conjunction with Microsoft Office 2010 SP1, does not properly restrict configuration options, which allows local users to gain privileges by starting Internet Explorer from the IME toolbar, aka "Chinese IME Vulnerability."

    Published: 11 Sept 2013
    6.9
    Medium

    CVE-2013-3862

    Last Modified: 11 Apr 2025

    Double free vulnerability in Microsoft Windows 7 and Server 2008 R2 SP1 allows local users to gain privileges via a crafted service description that is not properly handled by services.exe in the Service Control Manager (SCM), aka "Service Control Manager Double Free Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3863

    Last Modified: 11 Apr 2025

    Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allow remote attackers to execute arbitrary code via a crafted OLE object in a file, aka "OLE Property Vulnerability."

    Published: 11 Sept 2013
    7.2
    High

    CVE-2013-3866

    Last Modified: 11 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3870

    Last Modified: 11 Apr 2025

    Double free vulnerability in Microsoft Outlook 2007 SP3 and 2010 SP1 and SP2 allows remote attackers to execute arbitrary code by including many nested S/MIME certificates in an e-mail message, aka "Message Certificate Vulnerability."

    Published: 11 Sept 2013
    5
    Medium

    CVE-2013-0081

    Last Modified: 11 Apr 2025

    Microsoft SharePoint Portal Server 2003 SP3 and SharePoint Server 2007 SP3, 2010 SP1 and SP2, and 2013 do not properly process unassigned workflows, which allows remote attackers to cause a denial of service (W3WP process hang) via a crafted URL, aka "SharePoint Denial of Service Vulnerability."

    Published: 11 Sept 2013
    7.2
    High

    CVE-2013-1341

    Last Modified: 11 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, and Windows 8 allows local users to gain privileges via a crafted application, aka "Win32k Multiple Fetch Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3155

    Last Modified: 11 Apr 2025

    Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Access file, aka "Access Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3157.

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3156

    Last Modified: 11 Apr 2025

    Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Access file, aka "Access File Format Memory Corruption Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3157

    Last Modified: 11 Apr 2025

    Microsoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Access file, aka "Access Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3155.

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3158

    Last Modified: 11 Apr 2025

    Microsoft Excel 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."

    Published: 11 Sept 2013
    4.3
    Medium

    CVE-2013-3180

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 and SP2 and 2013 allows remote attackers to inject arbitrary web script or HTML via a crafted POST request, aka "POST XSS Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3202

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3203

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3201, CVE-2013-3206, CVE-2013-3207, and CVE-2013-3209.

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3204

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 11 Sept 2013
    9.3
    Critical

    CVE-2013-3205

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 11 Sept 2013