CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2013-4277

    Last Modified: 11 Apr 2025

    Svnserve in Apache Subversion 1.4.0 through 1.7.12 and 1.8.0 through 1.8.1 allows local users to overwrite arbitrary files or kill arbitrary processes via a symlink attack on the file specified by the --pid-file option.

    Published: 30 Aug 2013
    6.8
    Medium

    CVE-2013-7010

    Last Modified: 11 Apr 2025

    Multiple integer signedness errors in libavcodec/dsputil.c in FFmpeg before 2.1 allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted data.

    Published: 30 Aug 2013
    8.8
    High

    CVE-2013-4246

    Last Modified: 20 Apr 2025

    libsvn_fs_fs/fs_fs.c in Apache Subversion 1.8.x before 1.8.2 might allow remote authenticated users with commit access to corrupt FSFS repositories and cause a denial of service or obtain sensitive information by editing packed revision properties.

    Published: 30 Aug 2013
    2.4
    Low

    CVE-2013-7393

    Last Modified: 12 Apr 2025

    The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfile option is used. NOTE: this issue was SPLIT from CVE-2013-4262 based on different affected versions (ADT3).

    Published: 30 Aug 2013
    3.5
    Low

    CVE-2013-4003

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3.1.1, and 8, allow remote authenticated users to inject arbitrary web script or HTML via (1) unspecified input to WebProcess.srv, (2) unspecified input to html/en/default/actionHandler/queryHandler.jsp, or (3) unspecified input in a portalSectionId action to html/en/default/reportTemplate/hGridTopQuery.jsp.

    Published: 29 Aug 2013
    7.8
    High

    CVE-2013-5209

    Last Modified: 11 Apr 2025

    The sctp_send_initiate_ack function in sys/netinet/sctp_output.c in the SCTP implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE does not properly initialize the state-cookie data structure, which allows remote attackers to obtain sensitive information from kernel stack memory by reading packet data in INIT-ACK chunks.

    Published: 29 Aug 2013
    9.3
    Critical

    CVE-2013-3466

    Last Modified: 11 Apr 2025

    The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.

    Published: 29 Aug 2013
    7.8
    High

    CVE-2013-3468

    Last Modified: 11 Apr 2025

    The Cisco Unified IP Phone 8945 with software 9.3(2) allows remote attackers to cause a denial of service (device hang) via a malformed PNG file, aka Bug ID CSCud04270.

    Published: 29 Aug 2013
    6.8
    Medium

    CVE-2013-3472

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Enterprise License Manager (ELM) in Cisco Unified Communications Manager (CM) allows remote attackers to hijack the authentication of arbitrary users for requests that make ELM modifications, aka Bug ID CSCui58210.

    Published: 29 Aug 2013
    4.3
    Medium

    CVE-2013-5588

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the step parameter to install/index.php or (2) the id parameter to cacti/host.php.

    Published: 29 Aug 2013
    7.5
    High

    CVE-2013-5589

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 29 Aug 2013
    4.3
    Medium

    CVE-2013-5645

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Roundcube webmail before 0.9.3 allow user-assisted remote attackers to inject arbitrary web script or HTML via the body of a message visited in (1) new or (2) draft mode, related to compose.inc; and (3) might allow remote authenticated users to inject arbitrary web script or HTML via an HTML signature, related to save_identity.inc.

    Published: 29 Aug 2013
    3.5
    Low

    CVE-2013-5646

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.

    Published: 29 Aug 2013
    7.5
    High

    CVE-2013-5647

    Last Modified: 11 Apr 2025

    lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.

    Published: 29 Aug 2013
    6.8
    Medium

    CVE-2013-5648

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.

    Published: 29 Aug 2013
    4.3
    Medium

    CVE-2013-3471

    Last Modified: 11 Apr 2025

    The captive portal application in Cisco Identity Services Engine (ISE) allows remote attackers to discover cleartext usernames and passwords by leveraging unspecified use of hidden form fields in an HTML document, aka Bug ID CSCug02515.

    Published: 29 Aug 2013
    4.7
    Medium

    CVE-2013-2891

    Last Modified: 11 Apr 2025

    drivers/hid/hid-steelseries.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_STEELSERIES is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.

    Published: 29 Aug 2013
    4.7
    Medium

    CVE-2013-2896

    Last Modified: 11 Apr 2025

    drivers/hid/hid-ntrig.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_NTRIG is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) via a crafted device.

    Published: 29 Aug 2013
    6.9
    Medium

    CVE-2013-4291

    Last Modified: 11 Apr 2025

    The virSecurityManagerSetProcessLabel function in libvirt 0.10.2.7, 1.0.5.5, and 1.1.1, when the domain has read an uid:gid label, does not properly set group memberships, which allows local users to gain privileges.

    Published: 29 Aug 2013
    4.3
    Medium

    CVE-2013-4298

    Last Modified: 11 Apr 2025

    The ReadGIFImage function in coders/gif.c in ImageMagick before 6.7.8-8 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted comment in a GIF image.

    Published: 29 Aug 2013
    6.2
    Medium

    CVE-2013-2888

    Last Modified: 11 Apr 2025

    Multiple array index errors in drivers/hid/hid-core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11 allow physically proximate attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted device that provides an invalid Report ID.

    Published: 29 Aug 2013
    4.7
    Medium

    CVE-2013-2892

    Last Modified: 11 Apr 2025

    drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.

    Published: 29 Aug 2013
    4.7
    Medium

    CVE-2013-2893

    Last Modified: 11 Apr 2025

    The Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_LOGITECH_FF, CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device, related to (1) drivers/hid/hid-lgff.c, (2) drivers/hid/hid-lg3ff.c, and (3) drivers/hid/hid-lg4ff.c.

    Published: 29 Aug 2013
    4.7
    Medium

    CVE-2013-2894

    Last Modified: 11 Apr 2025

    drivers/hid/hid-lenovo-tpkbd.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LENOVO_TPKBD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.

    Published: 29 Aug 2013
    5.4
    Medium

    CVE-2013-2895

    Last Modified: 11 Apr 2025

    drivers/hid/hid-logitech-dj.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_LOGITECH_DJ is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) or obtain sensitive information from kernel memory via a crafted device.

    Published: 29 Aug 2013
    1.9
    Low

    CVE-2013-2898

    Last Modified: 11 Apr 2025

    drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted device.

    Published: 29 Aug 2013
    5
    Medium

    CVE-2013-5651

    Last Modified: 11 Apr 2025

    The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a crafted bitmap, as demonstrated by a large nodeset value to numatune.

    Published: 29 Aug 2013
    4.7
    Medium

    CVE-2013-2889

    Last Modified: 11 Apr 2025

    drivers/hid/hid-zpff.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_ZEROPLUS is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.

    Published: 29 Aug 2013
    4.7
    Medium

    CVE-2013-2890

    Last Modified: 11 Apr 2025

    drivers/hid/hid-sony.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SONY is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.

    Published: 29 Aug 2013
    4.7
    Medium

    CVE-2013-2897

    Last Modified: 11 Apr 2025

    Multiple array index errors in drivers/hid/hid-multitouch.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_MULTITOUCH is enabled, allow physically proximate attackers to cause a denial of service (heap memory corruption, or NULL pointer dereference and OOPS) via a crafted device.

    Published: 29 Aug 2013
    4.7
    Medium

    CVE-2013-2899

    Last Modified: 11 Apr 2025

    drivers/hid/hid-picolcd_core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PICOLCD is enabled, allows physically proximate attackers to cause a denial of service (NULL pointer dereference and OOPS) via a crafted device.

    Published: 29 Aug 2013
    2.1
    Low

    CVE-2013-4292

    Last Modified: 11 Apr 2025

    libvirt 1.1.0 and 1.1.1 allows local users to cause a denial of service (memory consumption) via a large number of domain migrate parameters in certain RPC calls in (1) daemon/remote.c and (2) remote/remote_driver.c.

    Published: 29 Aug 2013
    5
    Medium

    CVE-2013-2178

    Last Modified: 11 Apr 2025

    The apache-auth.conf, apache-nohome.conf, apache-noscript.conf, and apache-overflows.conf files in Fail2ban before 0.8.10 do not properly validate log messages, which allows remote attackers to block arbitrary IP addresses via certain messages in a request.

    Published: 28 Aug 2013
    5.8
    Medium

    CVE-2013-2123

    Last Modified: 11 Apr 2025

    The Node access user reference module 6.x-3.x before 6.x-3.5 and 7.x-3.x before 7.x-3.10 for Drupal does not properly restrict access to content containing a user reference field when the author update/delete grants are enabled and the author's user account is deleted, which allows remote attackers to modify the content via unspecified vectors.

    Published: 28 Aug 2013
    7.5
    High

    CVE-2013-2247

    Last Modified: 11 Apr 2025

    The Fast Permissions Administration module 6.x-2.x before 6.x-2.5 and 7.x-2.x before 7.x-2.3 for Drupal does not properly restrict access to the modal content callback, which allows remote attackers to obtain unspecified access to the permissions edit form.

    Published: 28 Aug 2013
    2.1
    Low

    CVE-2013-4138

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Hatch theme 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with the "Administer content," "Create new article," or "Edit any article type content" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 28 Aug 2013
    5
    Medium

    CVE-2013-4139

    Last Modified: 11 Apr 2025

    The Stage File Proxy module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to cause a denial of service (file operations performance degradation and failure) via a large number of requests.

    Published: 28 Aug 2013
    4.3
    Medium

    CVE-2013-2197

    Last Modified: 11 Apr 2025

    The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal, when using the login delay option, allows remote attackers to cause a denial of service (CPU consumption) via a large number of failed login attempts.

    Published: 28 Aug 2013
    4.3
    Medium

    CVE-2013-4272

    Last Modified: 11 Apr 2025

    The BOTCHA Spam Prevention module 7.x-1.x before 7.x-1.6, 7.x-2.x before 7.x-2.1, and 7.x-3.x before 7.x-3.3 for Drupal, when the debugging level is set to 5 or 6, logs the content of submitted forms, which allows context-dependent users to obtain sensitive information such as usernames and passwords by reading the log file.

    Published: 28 Aug 2013
    2.1
    Low

    CVE-2013-4274

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the password_policy_admin_view function in password_policy.admin.inc in the Password Policy module 6.x-1.x before 6.x-1.6 and 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer policies" permission to inject arbitrary web script or HTML via the "Password Expiration Warning" field to the admin/config/people/password_policy/add page.

    Published: 28 Aug 2013
    5
    Medium

    CVE-2013-3271

    Last Modified: 11 Apr 2025

    EMC RSA Authentication Agent for PAM 7.0 before 7.0.2.1 enforces the maximum number of login attempts within the PAM-enabled application codebase, instead of within the Agent codebase, which makes it easier for remote attackers to discover correct login credentials via a brute-force attack.

    Published: 28 Aug 2013
    4
    Medium

    CVE-2013-4039

    Last Modified: 11 Apr 2025

    IBM WebSphere Extended Deployment Compute Grid 8.0 before 8.0.0.3 allows remote authenticated users to obtain sensitive information, and consequently bypass intended access restrictions on jobs, via unspecified vectors.

    Published: 28 Aug 2013
    7.2
    High

    CVE-2013-3077

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the IP_MSFILTER and IPV6_MSFILTER features in (1) sys/netinet/in_mcast.c and (2) sys/netinet6/in6_mcast.c in the multicast implementation in the kernel in FreeBSD 8.3 through 9.2-PRERELEASE allow local users to bypass intended restrictions on kernel-memory read and write operations, and consequently gain privileges, via vectors involving a large number of source-filter entries.

    Published: 28 Aug 2013
    7.8
    High

    CVE-2013-2353

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in HP StoreOnce D2D Backup System 1.x before 1.2.19 and 2.x before 2.3.0 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 28 Aug 2013
    7.6
    High

    CVE-2013-3582

    Last Modified: 11 Apr 2025

    Buffer overflow in Dell BIOS on Dell Latitude D###, E####, XT2, and Z600 devices, and Dell Precision M#### devices, allows local users to bypass intended BIOS signing requirements and install arbitrary BIOS images by leveraging administrative privileges and providing a crafted rbu_packet.pktNum value in conjunction with a crafted rbu_packet.pktSize value.

    Published: 28 Aug 2013
    4.6
    Medium

    CVE-2013-4033

    Last Modified: 11 Apr 2025

    IBM DB2 and DB2 Connect 9.7 through FP8, 9.8 through FP5, 10.1 through FP2, and 10.5 through FP1 allow remote authenticated users to execute DML statements by leveraging EXPLAIN authority.

    Published: 28 Aug 2013
    9.3
    Critical

    CVE-2013-2782

    Last Modified: 11 Apr 2025

    Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

    Published: 28 Aug 2013
    5
    Medium

    CVE-2013-3585

    Last Modified: 11 Apr 2025

    Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page.

    Published: 28 Aug 2013
    5
    Medium

    CVE-2013-3598

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in servlet/CreateTemplateServlet in SearchBlox before 7.5 build 1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the name parameter.

    Published: 28 Aug 2013
    7.1
    High

    CVE-2013-2804

    Last Modified: 11 Apr 2025

    The DNP Master Driver in Software Toolbox TOP Server before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically proximate attackers to cause a denial of service (master-station infinite loop) via crafted input over a serial line.

    Published: 28 Aug 2013