CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-2583

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev16, 6.22.0 before rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allow remote attackers to inject arbitrary web script or HTML via (1) a javascript: URL, (2) malformed nested SCRIPT elements, (3) a mail signature, or (4) JavaScript code within an image file.

    Published: 5 Sept 2013
    4.3
    Medium

    CVE-2013-3106

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange AppSuite and Server before 6.20.7 rev18, 6.22.0 before rev16, 6.22.1 before rev19, 7.0.1 before rev7, 7.0.2 before rev11, and 7.2.0 before rev8 allow remote attackers to inject arbitrary web script or HTML via (1) embedded VBScript, (2) object/data Base64 content, (3) a Content-Type header, or (4) UTF-16 encoding, aka Bug IDs 25957, 26237, 26243, and 26244.

    Published: 5 Sept 2013
    6
    Medium

    CVE-2013-3276

    Last Modified: 11 Apr 2025

    EMC RSA Archer GRC 5.x before 5.4 allows remote authenticated users to bypass intended access restrictions and complete a login by leveraging a deactivated account.

    Published: 5 Sept 2013
    5.8
    Medium

    CVE-2013-3277

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in EMC RSA Archer GRC 5.x before 5.4 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 5 Sept 2013
    3.5
    Low

    CVE-2013-1648

    Last Modified: 11 Apr 2025

    The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue.

    Published: 5 Sept 2013
    5
    Medium

    CVE-2013-2582

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in the redirect servlet in Open-Xchange AppSuite and Server before 6.22.0 rev15, 6.22.1 before rev17, 7.0.1 before rev6, and 7.0.2 before rev7 allows remote attackers to inject arbitrary HTTP headers and conduct open redirect attacks by leveraging improper sanitization of whitespace characters.

    Published: 5 Sept 2013
    3.5
    Low

    CVE-2013-4790

    Last Modified: 11 Apr 2025

    Open-Xchange AppSuite before 7.0.2 rev14, 7.2.0 before rev11, 7.2.1 before rev10, and 7.2.2 before rev9 relies on user-supplied data to predict the IMAP server hostname for an external domain name, which allows remote authenticated users to discover e-mail credentials of other users in opportunistic circumstances via a manual-mode association of a personal e-mail address with the hostname of a crafted IMAP server.

    Published: 5 Sept 2013
    6.8
    Medium

    CVE-2013-3479

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the ShareThis plugin before 7.0.6 for WordPress allows remote attackers to hijack the authentication of administrators for requests that modify this plugin's settings.

    Published: 5 Sept 2013
    6.8
    Medium

    CVE-2013-5471

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the web framework in Cisco Global Site Selector (GSS) allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuh42164.

    Published: 5 Sept 2013
    6.9
    Medium

    CVE-2013-4169

    Last Modified: 11 Apr 2025

    GNOME Display Manager (gdm) before 2.21.1 allows local users to change permissions of arbitrary directories via a symlink attack on /tmp/.X11-unix/.

    Published: 5 Sept 2013
    4.3
    Medium

    CVE-2013-1661

    Last Modified: 11 Apr 2025

    VMware ESXi 4.0 through 5.1, and ESX 4.0 and 4.1, does not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to cause a denial of service (unhandled exception and application crash) by modifying the client-server data stream.

    Published: 4 Sept 2013
    5
    Medium

    CVE-2013-3469

    Last Modified: 11 Apr 2025

    Cisco Mobility Services Engine does not properly set up the Oracle SSL service, which allows remote attackers to obtain an unauthenticated session to the database-replication port, and consequently obtain sensitive information, via an SSL connection, aka Bug ID CSCue50794.

    Published: 4 Sept 2013
    5
    Medium

    CVE-2013-5470

    Last Modified: 11 Apr 2025

    Cisco Secure Access Control System (ACS) does not properly handle requests to read from the TACACS+ socket, which allows remote attackers to cause a denial of service (process crash) via malformed TCP packets, aka Bug ID CSCuh12488.

    Published: 4 Sept 2013
    3.6
    Low

    CVE-2013-4157

    Last Modified: 11 Apr 2025

    Red Hat Storage 2.0 allows local users to overwrite arbitrary files via a symlink attack on the (1) e, (2) local-bricks.list, (3) bricks.err, or (4) limits.conf files in /tmp.

    Published: 4 Sept 2013
    1.9
    Low

    CVE-2013-1921

    Last Modified: 11 Apr 2025

    PicketBox, as used in Red Hat JBoss Enterprise Application Platform before 6.1.1, allows local users to obtain the admin encryption key by reading the Vault data file.

    Published: 4 Sept 2013
    9.4
    Critical

    CVE-2013-2068

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to create and overwrite arbitrary files via a .. (dot dot) in the filename parameter to the (1) log, (2) upload, or (3) linuxpkgs method.

    Published: 4 Sept 2013
    4.3
    Medium

    CVE-2013-4314

    Last Modified: 11 Apr 2025

    The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

    Published: 4 Sept 2013
    5
    Medium

    CVE-2013-4180

    Last Modified: 11 Apr 2025

    The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.

    Published: 3 Sept 2013
    7.5
    High

    CVE-2013-4182

    Last Modified: 11 Apr 2025

    app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request.

    Published: 3 Sept 2013
    4
    Medium

    CVE-2013-4297

    Last Modified: 11 Apr 2025

    The virFileNBDDeviceAssociate function in util/virfile.c in libvirt 1.1.2 and earlier allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and crash) via unspecified vectors.

    Published: 3 Sept 2013
    7.5
    High

    CVE-2013-2185

    Last Modified: 11 Apr 2025

    The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue

    Published: 3 Sept 2013
    7.5
    High

    CVE-2013-7450

    Last Modified: 20 Apr 2025

    Pulp before 2.3.0 uses the same the same certificate authority key and certificate for all installations.

    Published: 1 Sept 2013
    4.3
    Medium

    CVE-2012-6590

    Last Modified: 11 Apr 2025

    The web-based management UI in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote attackers to obtain verbose error information via crafted input, aka Ref ID 33139.

    Published: 31 Aug 2013
    9
    Critical

    CVE-2012-6591

    Last Modified: 11 Apr 2025

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 31116.

    Published: 31 Aug 2013
    5
    Medium

    CVE-2012-6596

    Last Modified: 11 Apr 2025

    Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.3 stores cleartext LDAP bind passwords in authd.log, which allows context-dependent attackers to obtain sensitive information by reading this file, aka Ref ID 35493.

    Published: 31 Aug 2013
    9
    Critical

    CVE-2012-6598

    Last Modified: 11 Apr 2025

    The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33080.

    Published: 31 Aug 2013
    9
    Critical

    CVE-2012-6600

    Last Modified: 11 Apr 2025

    The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 34502.

    Published: 31 Aug 2013
    9
    Critical

    CVE-2012-6604

    Last Modified: 11 Apr 2025

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 35249.

    Published: 31 Aug 2013
    4.3
    Medium

    CVE-2013-5663

    Last Modified: 11 Apr 2025

    The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identification of HTTP traffic as SIP traffic, aka Ref ID 47195.

    Published: 31 Aug 2013
    4.3
    Medium

    CVE-2013-5664

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908.

    Published: 31 Aug 2013
    9
    Critical

    CVE-2012-6594

    Last Modified: 11 Apr 2025

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11, 4.0.x before 4.0.8, and 4.1.x before 4.1.1 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34299.

    Published: 31 Aug 2013
    9
    Critical

    CVE-2012-6595

    Last Modified: 11 Apr 2025

    The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34595.

    Published: 31 Aug 2013
    6.3
    Medium

    CVE-2012-6597

    Last Modified: 11 Apr 2025

    Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to cause a denial of service (management-server crash) by using the command-line interface for a crafted command, aka Ref ID 35254.

    Published: 31 Aug 2013
    9
    Critical

    CVE-2012-6599

    Last Modified: 11 Apr 2025

    The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 and 4.1.x before 4.1.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33476.

    Published: 31 Aug 2013
    9
    Critical

    CVE-2012-6602

    Last Modified: 11 Apr 2025

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 30122.

    Published: 31 Aug 2013
    10
    Critical

    CVE-2012-6603

    Last Modified: 11 Apr 2025

    The web management UI in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to bypass authentication and obtain administrator privileges via unspecified vectors, aka Ref ID 37034.

    Published: 31 Aug 2013
    5.8
    Medium

    CVE-2012-6606

    Last Modified: 11 Apr 2025

    Palo Alto Networks GlobalProtect before 1.1.7, and NetConnect, does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof portal servers and obtain sensitive information via a crafted certificate.

    Published: 31 Aug 2013
    10
    Critical

    CVE-2012-6592

    Last Modified: 11 Apr 2025

    Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 31091.

    Published: 31 Aug 2013
    10
    Critical

    CVE-2012-6593

    Last Modified: 11 Apr 2025

    Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 30088.

    Published: 31 Aug 2013
    10
    Critical

    CVE-2012-6601

    Last Modified: 11 Apr 2025

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.12, 4.0.x before 4.0.10, and 4.1.x before 4.1.4 allows remote attackers to execute arbitrary code via unspecified vectors, aka Ref ID 36983.

    Published: 31 Aug 2013
    9
    Critical

    CVE-2012-6605

    Last Modified: 11 Apr 2025

    The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11 and 4.0.x before 4.0.9 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Ref ID 34896.

    Published: 31 Aug 2013
    6.9
    Medium

    CVE-2013-3485

    Last Modified: 11 Apr 2025

    Multiple untrusted search path vulnerabilities in Soda PDF 5.1.183.10520 allow local users to gain privileges via a Trojan horse (1) dwmapi.dll or (2) api-ms-win-core-localregistry-l1-1-0.dll file in the current working directory.

    Published: 30 Aug 2013
    5
    Medium

    CVE-2013-4702

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the doApiAction function in data/class/api/SC_Api_Operation.php in LOCKON EC-CUBE 2.12.0 through 2.12.5 on Windows allow remote attackers to read arbitrary files via vectors involving a (1) Operation, (2) Service, (3) Style, (4) Validate, or (5) Version value.

    Published: 30 Aug 2013
    7.1
    High

    CVE-2013-5469

    Last Modified: 11 Apr 2025

    The TCP implementation in Cisco IOS does not properly implement the transitions from the ESTABLISHED state to the CLOSED state, which allows remote attackers to cause a denial of service (flood of ACK packets) via a crafted series of ACK and FIN packets, aka Bug ID CSCtz14399.

    Published: 30 Aug 2013
    6.3
    Medium

    CVE-2013-3474

    Last Modified: 11 Apr 2025

    The Web Administrator Interface on Cisco Wireless LAN Controller (WLC) devices allows remote authenticated users to cause a denial of service (device crash) by leveraging membership in the Full Manager managers group, Read Only managers group, or Lobby Ambassador managers group, and sending a request that (1) lacks a parameter value or (2) contains a malformed parameter value, aka Bug IDs CSCuh14313, CSCuh14159, CSCuh14368, and CSCuh14436.

    Published: 30 Aug 2013
    5
    Medium

    CVE-2013-3470

    Last Modified: 11 Apr 2025

    The RIP process in Cisco IOS XR allows remote attackers to cause a denial of service (process crash) via a crafted version-2 RIP packet, aka Bug ID CSCue46731.

    Published: 30 Aug 2013
    4.3
    Medium

    CVE-2012-5744

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the guest portal in Cisco Identity Services Engine (ISE) Software allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCud11139 and CSCug02904.

    Published: 30 Aug 2013
    4.3
    Medium

    CVE-2013-3463

    Last Modified: 11 Apr 2025

    The protocol-inspection feature on Cisco Adaptive Security Appliances (ASA) devices does not properly implement the idle timeout, which allows remote attackers to cause a denial of service (connection-table exhaustion) via crafted requests that use an inspected protocol, aka Bug ID CSCuh13899.

    Published: 30 Aug 2013
    4.6
    Medium

    CVE-2013-3467

    Last Modified: 11 Apr 2025

    Memory leak in the CLI component on Cisco Unified Computing System (UCS) 6100 Fabric Interconnect devices, in certain situations that lack a SPAN session, allows local users to cause a denial of service (memory consumption and device reset) via a (1) "show monitor session all" or (2) "show monitor session" command, aka Bug ID CSCug20103.

    Published: 30 Aug 2013
    2.4
    Low

    CVE-2013-4262

    Last Modified: 12 Apr 2025

    svnwcsub.py in Subversion 1.8.0 before 1.8.3, when using the --pidfile option and running in foreground mode, allows local users to gain privileges via a symlink attack on the pid file. NOTE: this issue was SPLIT due to different affected versions (ADT3). The irkerbridge.py issue is covered by CVE-2013-7393.

    Published: 30 Aug 2013