CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2013-5642

    Last Modified: 11 Apr 2025

    The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.x before 1.8.23.1, 10.x before 10.12.3, and 11.x before 11.5.1; Certified Asterisk 1.8.15 before 1.8.15-cert3 and 11.2 before 11.2-cert2; and Asterisk Digiumphones 10.x-digiumphones before 10.12.3-digiumphones allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and daemon crash) via an invalid SDP that defines a media description before the connection description in a SIP request.

    Published: 9 Sept 2013
    4.3
    Medium

    CVE-2013-5714

    Last Modified: 3 Nov 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ls/htmlchat.php in the VideoWhisper Live Streaming Integration plugin 4.25.3 and possibly earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) message parameter. NOTE: some of these details are obtained from third party information.

    Published: 9 Sept 2013
    5
    Medium

    CVE-2013-5641

    Last Modified: 11 Apr 2025

    The SIP channel driver (channels/chan_sip.c) in Asterisk Open Source 1.8.17.x through 1.8.22.x, 1.8.23.x before 1.8.23.1, and 11.x before 11.5.1 and Certified Asterisk 1.8.15 before 1.8.15-cert3 and 11.2 before 11.2-cert2 allows remote attackers to cause a denial of service (NULL pointer dereference, segmentation fault, and daemon crash) via an ACK with SDP to a previously terminated channel. NOTE: some of these details are obtained from third party information.

    Published: 9 Sept 2013
    7.1
    High

    CVE-2013-2791

    Last Modified: 11 Apr 2025

    MatrikonOPC SCADA DNP3 OPC Server 1.2.0 allows remote attackers to cause a denial of service (master-station daemon crash) via a malformed DNP3 TCP packet from the IP address of an outstation.

    Published: 9 Sept 2013
    7.8
    High

    CVE-2013-2793

    Last Modified: 11 Apr 2025

    Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet.

    Published: 9 Sept 2013
    4.9
    Medium

    CVE-2013-2794

    Last Modified: 11 Apr 2025

    Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line.

    Published: 9 Sept 2013
    9.3
    Critical

    CVE-2013-2803

    Last Modified: 11 Apr 2025

    ProSoft RadioLinx ControlScape before 6.00.040 uses a deficient PRNG algorithm and seeding strategy for passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published: 9 Sept 2013
    4.3
    Medium

    CVE-2013-2992

    Last Modified: 11 Apr 2025

    The Search component in IBM WebSphere Commerce 7.0 FP4 through FP6, in certain search-term association configurations, allows remote attackers to cause a denial of service via a crafted query.

    Published: 9 Sept 2013
    4
    Medium

    CVE-2013-4061

    Last Modified: 11 Apr 2025

    IBM Rational Policy Tester 8.5 before 8.5.0.5 does not properly check authorization for changes to the set of authentication hosts, which allows remote authenticated users to perform spoofing attacks involving an HTTP redirect via unspecified vectors.

    Published: 9 Sept 2013
    6.8
    Medium

    CVE-2013-4062

    Last Modified: 11 Apr 2025

    IBM Rational Policy Tester 8.5 before 8.5.0.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof Jazz Team servers, obtain sensitive information, and modify the client-server data stream via a crafted certificate.

    Published: 9 Sept 2013
    3.5
    Low

    CVE-2013-3031

    Last Modified: 11 Apr 2025

    A SQL stored procedure in the Universal Cache component in IBM solidDB 6.0.x before 6.0.1070, 6.3.x before 6.3.0.56, 6.5.x before 6.5.0.12, and 7.0.x before 7.0.0.4 allows remote authenticated users to cause a denial of service (uninitialized-memory access and daemon crash) via a call that includes named arguments and default parameter values, but does not include all of the expected arguments.

    Published: 9 Sept 2013
    4.3
    Medium

    CVE-2013-4287

    Last Modified: 11 Apr 2025

    Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote attackers to cause a denial of service (CPU consumption) via a crafted gem version that triggers a large amount of backtracking in a regular expression.

    Published: 9 Sept 2013
    5.9
    Medium

    CVE-2013-5661

    Last Modified: 21 Nov 2024

    Cache Poisoning issue exists in DNS Response Rate Limiting.

    Published: 9 Sept 2013
    5
    Medium

    CVE-2013-0531

    Last Modified: 11 Apr 2025

    The SSL implementation in IBM Security AppScan Enterprise before 8.7.0.1 enables cipher suites with weak encryption algorithms, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.

    Published: 8 Sept 2013
    1.7
    Low

    CVE-2013-2997

    Last Modified: 11 Apr 2025

    IBM Security AppScan Enterprise before 8.7 does not invalidate the session context upon a logout action, which allows remote attackers to hijack sessions by leveraging an unattended workstation.

    Published: 8 Sept 2013
    4
    Medium

    CVE-2013-3596

    Last Modified: 11 Apr 2025

    AdvancePro Advanceware allows remote authenticated users to obtain sensitive information about arbitrary customers' orders via a modified id parameter.

    Published: 8 Sept 2013
    7.1
    High

    CVE-2013-3458

    Last Modified: 11 Apr 2025

    Cisco Adaptive Security Appliances (ASA) devices, when SMP is used, do not properly process X.509 certificates, which allows remote attackers to cause a denial of service (device crash) via a large volume of (1) SSL or (2) TLS traffic, aka Bug ID CSCuh19462.

    Published: 8 Sept 2013
    10
    Critical

    CVE-2013-3609

    Last Modified: 11 Apr 2025

    The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices relies on JavaScript code on the client for authorization checks, which allows remote authenticated users to bypass intended access restrictions via a crafted request, related to the PrivilegeCallBack function.

    Published: 8 Sept 2013
    5.4
    Medium

    CVE-2013-5132

    Last Modified: 11 Apr 2025

    Apple AirPort Base Station Firmware before 7.6.4 does not properly handle incorrect frame lengths, which allows remote attackers to cause a denial of service (device crash) by associating with the access point and then sending a short frame.

    Published: 8 Sept 2013
    4.3
    Medium

    CVE-2013-5483

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in bookmarklet.jsp in Cisco SocialMiner allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCuh73868.

    Published: 8 Sept 2013
    10
    Critical

    CVE-2013-3607

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allow remote attackers to execute arbitrary code on the Baseboard Management Controller (BMC), as demonstrated by the (1) username or (2) password field in login.cgi.

    Published: 8 Sept 2013
    10
    Critical

    CVE-2013-3608

    Last Modified: 11 Apr 2025

    The web interface in the Intelligent Platform Management Interface (IPMI) implementation on Supermicro H8DC*, H8DG*, H8SCM-F, H8SGL-F, H8SM*, X7SP*, X8DT*, X8SI*, X9DAX-*, X9DB*, X9DR*, X9QR*, X9SBAA-F, X9SC*, X9SPU-F, and X9SR* devices allows remote authenticated users to execute arbitrary commands via shell metacharacters, as demonstrated by the IP address field in config_date_time.cgi.

    Published: 8 Sept 2013
    7.5
    High

    CVE-2013-4271

    Last Modified: 11 Apr 2025

    The default configuration of the ObjectRepresentation class in Restlet before 2.1.4 deserializes objects from untrusted sources, which allows remote attackers to execute arbitrary Java code via a serialized object, a different vulnerability than CVE-2013-4221.

    Published: 7 Sept 2013
    4.7
    Medium

    CVE-2013-6431

    Last Modified: 11 Apr 2025

    The fib6_add function in net/ipv6/ip6_fib.c in the Linux kernel before 3.11.5 does not properly implement error-code encoding, which allows local users to cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for an IPv6 SIOCADDRT ioctl call.

    Published: 7 Sept 2013
    4.3
    Medium

    CVE-2013-5707

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via crafted input containing a %22 sequence, a different issue than CVE-2013-3604.

    Published: 6 Sept 2013
    9.3
    Critical

    CVE-2013-1116

    Last Modified: 11 Apr 2025

    Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted ARF file, aka Bug IDs CSCue74147 and CSCub28383.

    Published: 6 Sept 2013
    9.3
    Critical

    CVE-2013-1117

    Last Modified: 11 Apr 2025

    Buffer overflow in the exception handler in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted WRF file, aka Bug ID CSCuc27639.

    Published: 6 Sept 2013
    9.3
    Critical

    CVE-2013-1118

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code via a crafted WRF file, aka Bug ID CSCuc27645.

    Published: 6 Sept 2013
    9.3
    Critical

    CVE-2013-1119

    Last Modified: 11 Apr 2025

    Buffer overflow in Cisco WebEx Recording Format (WRF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DHT index value in JPEG data within a WRF file, aka Bug ID CSCuc24503.

    Published: 6 Sept 2013
    9.3
    Critical

    CVE-2013-3599

    Last Modified: 11 Apr 2025

    userlogin.jsp in Coursemill Learning Management System (LMS) 6.6 and 6.8 allows remote attackers to gain privileges via a modified user-role value to home.html.

    Published: 6 Sept 2013
    8.5
    High

    CVE-2013-3600

    Last Modified: 11 Apr 2025

    Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to gain privileges via a modified userid value to unspecified functions.

    Published: 6 Sept 2013
    6
    Medium

    CVE-2013-3601

    Last Modified: 11 Apr 2025

    Coursemill Learning Management System (LMS) 6.6 does not properly restrict JSP function calls, which allows remote authenticated users to perform arbitrary JSP operations by leveraging the Student role and providing an op parameter.

    Published: 6 Sept 2013
    7.5
    High

    CVE-2013-3602

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in admindocumentworker.jsp in Coursemill Learning Management System (LMS) 6.6 allows remote authenticated users to execute arbitrary SQL commands via the docID parameter.

    Published: 6 Sept 2013
    4.3
    Medium

    CVE-2013-3603

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.

    Published: 6 Sept 2013
    4.3
    Medium

    CVE-2013-3604

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.6 allow remote attackers to inject arbitrary web script or HTML via crafted input.

    Published: 6 Sept 2013
    6.8
    Medium

    CVE-2013-3605

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Coursemill Learning Management System (LMS) 6.6 allows remote attackers to hijack the authentication of arbitrary users via vectors related to cookies.

    Published: 6 Sept 2013
    4.3
    Medium

    CVE-2012-5990

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Health Monitor Login pages in Cisco Prime Network Control System (NCS) and Wireless Control System (WCS) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug ID CSCud18375.

    Published: 6 Sept 2013
    9.3
    Critical

    CVE-2013-1115

    Last Modified: 11 Apr 2025

    Buffer overflow in Cisco WebEx Advanced Recording Format (ARF) player T27 LD before SP32 EP16, T27 L10N before SP32_ORION111, and T28 before T28.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ARF file, aka Bug IDs CSCue74118, CSCub28371, CSCud23401, and CSCud31109.

    Published: 6 Sept 2013
    4.3
    Medium

    CVE-2013-1228

    Last Modified: 11 Apr 2025

    Cisco Jabber on Windows does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and modify the client-server data stream via a crafted certificate, aka Bug ID CSCug30280.

    Published: 6 Sept 2013
    4.3
    Medium

    CVE-2013-5706

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser's HTML implementation, a different issue than CVE-2013-3603.

    Published: 6 Sept 2013
    6.8
    Medium

    CVE-2013-5708

    Last Modified: 11 Apr 2025

    Coursemill Learning Management System (LMS) 6.8 constructs secret tokens based on time values, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via vectors related to cookies, a different vulnerability than CVE-2013-3605.

    Published: 6 Sept 2013
    3.3
    Low

    CVE-2013-4209

    Last Modified: 21 Nov 2024

    Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.

    Published: 6 Sept 2013
    5
    Medium

    CVE-2013-1647

    Last Modified: 11 Apr 2025

    Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter, as demonstrated by (1) the location parameter to ajax/redirect or (2) multiple infostore URIs.

    Published: 5 Sept 2013
    5.8
    Medium

    CVE-2013-1651

    Last Modified: 11 Apr 2025

    OXUpdater in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof update servers and install arbitrary software via a crafted certificate.

    Published: 5 Sept 2013
    4.9
    Medium

    CVE-2013-5035

    Last Modified: 11 Apr 2025

    Multiple race conditions in HtmlCleaner before 2.6, as used in Open-Xchange AppSuite 7.2.2 before rev13 and other products, allow remote authenticated users to read the private e-mail of other persons in opportunistic circumstances by leveraging lack of thread safety and performing a rapid series of (1) mail-sending or (2) draft-saving operations.

    Published: 5 Sept 2013
    3.5
    Low

    CVE-2013-5698

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Open-Xchange AppSuite and Server before 6.22.0 rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allows remote authenticated users to inject arbitrary web script or HTML via a delivery=view action, aka Bug ID 26373, a different vulnerability than CVE-2013-3106.

    Published: 5 Sept 2013
    4
    Medium

    CVE-2013-1645

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the publication template path.

    Published: 5 Sept 2013
    4.3
    Medium

    CVE-2013-1646

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary web script or HTML via (1) invalid JSON data in a mail-sending POST request, (2) an arbitrary parameter to servlet/TestServlet, (3) a javascript: URL in a standalone-mode action to a UWA module, (4) an infostore attachment, (5) JavaScript code in a contact image, (6) an RSS feed, or (7) a signature.

    Published: 5 Sept 2013
    4.3
    Medium

    CVE-2013-1649

    Last Modified: 11 Apr 2025

    Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithms for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

    Published: 5 Sept 2013
    2.1
    Low

    CVE-2013-1650

    Last Modified: 11 Apr 2025

    Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses weak permissions (group "other" readable) under opt/open-xchange/etc/, which allows local users to obtain sensitive information via standard filesystem operations.

    Published: 5 Sept 2013