CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-3584

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Corporater EPM Suite allows remote attackers to inject arbitrary web script or HTML via the customerId parameter to an unspecified component.

    Published: 28 Aug 2013
    7.6
    High

    CVE-2013-3586

    Last Modified: 11 Apr 2025

    Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.

    Published: 28 Aug 2013
    5
    Medium

    CVE-2013-3597

    Last Modified: 11 Apr 2025

    servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action.

    Published: 28 Aug 2013
    6.8
    Medium

    CVE-2013-3583

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in saveProperties.html in Corporater EPM Suite allows remote attackers to hijack the authentication of arbitrary users for requests that change passwords.

    Published: 28 Aug 2013
    6.8
    Medium

    CVE-2013-3590

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 7.5 build 1 allows remote attackers to execute arbitrary code by uploading an executable file with the image/jpeg content type, and then accessing this file via unspecified vectors, as demonstrated by access to a JSP file.

    Published: 28 Aug 2013
    5
    Medium

    CVE-2013-4283

    Last Modified: 11 Apr 2025

    ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation request.

    Published: 28 Aug 2013
    4.3
    Medium

    CVE-2013-1438

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in dcraw 0.8.x through 0.8.9, as used in libraw, ufraw, shotwell, and other products, allows context-dependent attackers to cause a denial of service via a crafted photo file that triggers a (1) divide-by-zero, (2) infinite loop, or (3) NULL pointer dereference.

    Published: 28 Aug 2013
    4.3
    Medium

    CVE-2013-1439

    Last Modified: 11 Apr 2025

    The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.

    Published: 28 Aug 2013
    4.3
    Medium

    CVE-2013-0566

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the (1) Accelerator JSPs, (2) Organization Administration Console JSPs, and (3) Administration Console JSPs in WebSphere Commerce Tools in IBM WebSphere Commerce 5.6.1.0 through 5.6.1.5, 6.0.0.0 through 6.0.0.11, and 7.0.0.0 through 7.0.0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Aug 2013
    3.5
    Low

    CVE-2013-0586

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 27 Aug 2013
    3.5
    Low

    CVE-2013-0590

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0591.

    Published: 27 Aug 2013
    Unknown

    CVE-2013-4266

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5123. Reason: This candidate is a reservation duplicate of CVE-2013-5123. Notes: All CVE users should reference CVE-2013-5123 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Aug 2013
    3.5
    Low

    CVE-2013-0591

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3, a different vulnerability than CVE-2013-0590.

    Published: 27 Aug 2013
    4.3
    Medium

    CVE-2013-0595

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in iNotes 8.5.x in IBM Lotus Domino 8.5 before 8.5.3 FP5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka SPR PTHN95XNR3.

    Published: 27 Aug 2013
    2.1
    Low

    CVE-2013-2978

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2988.

    Published: 27 Aug 2013
    2.6
    Low

    CVE-2013-2988

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1, 10.1.1, 10.2, and 10.2.1 allows remote authenticated users to read files by leveraging the Report Author privilege, a different vulnerability than CVE-2013-2978.

    Published: 27 Aug 2013
    9.3
    Critical

    CVE-2013-4973

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code via a crafted .rmp file.

    Published: 27 Aug 2013
    9.3
    Critical

    CVE-2013-4974

    Last Modified: 11 Apr 2025

    RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed RealMedia file.

    Published: 27 Aug 2013
    Unknown

    CVE-2013-4328

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-4238. Reason: This candidate is a duplicate of CVE-2013-4238. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2013-4238 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 27 Aug 2013
    4.3
    Medium

    CVE-2013-4766

    Last Modified: 11 Apr 2025

    The gather log service in Eucalyptus before 3.3.1 allows remote attackers to read log files via an unspecified request to the (1) Cluster Controller (CC) or (2) Node Controller (NC) component.

    Published: 27 Aug 2013
    7.1
    High

    CVE-2013-3461

    Last Modified: 11 Apr 2025

    Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote attackers to cause a denial of service (memory and CPU consumption, and service disruption) via a flood of UDP packets to port 5060, aka Bug ID CSCub35869.

    Published: 25 Aug 2013
    4.7
    Medium

    CVE-2013-4205

    Last Modified: 11 Apr 2025

    Memory leak in the unshare_userns function in kernel/user_namespace.c in the Linux kernel before 3.10.6 allows local users to cause a denial of service (memory consumption) via an invalid CLONE_NEWUSER unshare call.

    Published: 25 Aug 2013
    2.1
    Low

    CVE-2013-4217

    Last Modified: 11 Apr 2025

    The OSAL_Crypt_SetEncryptedPassword function in InfraStack/OSDependent/Linux/OSAL/Services/wimax_osal_crypt_services.c in the OSAL crypt module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices logs a cleartext password during certain attempts to set a password, which allows local users to obtain sensitive information by reading a log file.

    Published: 25 Aug 2013
    2.1
    Low

    CVE-2013-4218

    Last Modified: 11 Apr 2025

    The InitMethodAndPassword function in InfraStack/OSAgnostic/WiMax/Agents/Supplicant/Source/SupplicantAgent.c in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses the same RSA private key in supplicant_key.pem on all systems, which allows local users to obtain sensitive information via unspecified decryption operations.

    Published: 25 Aug 2013
    7.5
    High

    CVE-2013-4219

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices allow remote attackers to cause a denial of service (component crash) or possibly execute arbitrary code via an L5 connection with a crafted PDU value that triggers a heap-based buffer overflow within (1) L5SocketsDispatcher.c or (2) L5Connector.c.

    Published: 25 Aug 2013
    7.5
    High

    CVE-2010-5289

    Last Modified: 11 Apr 2025

    Buffer overflow in the Authenticate method in the INCREDISPOOLERLib.Pop ActiveX control in ImSpoolU.dll in IncrediMail 2.0 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a long string in the first argument.

    Published: 25 Aug 2013
    4.3
    Medium

    CVE-2012-6585

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php in MYRE Realty Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter.

    Published: 25 Aug 2013
    7.5
    High

    CVE-2012-6586

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in MYRE Vacation Rental Software allow remote attackers to execute arbitrary SQL commands via the (1) garage1 or (2) bathrooms1 parameter to vacation/1_mobile/search.php, or (3) unspecified input to vacation/widgate/request_more_information.php.

    Published: 25 Aug 2013
    4.3
    Medium

    CVE-2012-6587

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in vacation/1_mobile/alert_members.php in MYRE Vacation Rental Software allows remote attackers to inject arbitrary web script or HTML via the link_idd parameter in a login action.

    Published: 25 Aug 2013
    7.5
    High

    CVE-2012-6588

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in links.php in MYRE Business Directory allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Published: 25 Aug 2013
    4.3
    Medium

    CVE-2012-6589

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in search.php in MYRE Business Directory allows remote attackers to inject arbitrary web script or HTML via the look parameter.

    Published: 25 Aug 2013
    7.8
    High

    CVE-2013-3387

    Last Modified: 11 Apr 2025

    Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (disk consumption) via a flood of TCP packets to port 5400, leading to large error-log files, aka Bug ID CSCua42724.

    Published: 25 Aug 2013
    7.8
    High

    CVE-2013-3388

    Last Modified: 11 Apr 2025

    Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets to port 44444, aka Bug ID CSCtz92776.

    Published: 25 Aug 2013
    7.8
    High

    CVE-2013-3389

    Last Modified: 11 Apr 2025

    Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets to port (1) 61615 or (2) 61616, aka Bug ID CSCtz90114.

    Published: 25 Aug 2013
    7.8
    High

    CVE-2013-3390

    Last Modified: 11 Apr 2025

    Memory leak in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.x before 9.2(1) allows remote attackers to cause a denial of service (memory consumption) via a flood of TCP packets, aka Bug ID CSCub59158.

    Published: 25 Aug 2013
    7.8
    High

    CVE-2013-3459

    Last Modified: 11 Apr 2025

    Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6a does not properly handle errors, which allows remote attackers to cause a denial of service (service disruption) via malformed registration messages, aka Bug ID CSCuf93466.

    Published: 25 Aug 2013
    7.8
    High

    CVE-2013-3460

    Last Modified: 11 Apr 2025

    Memory leak in Cisco Unified Communications Manager (Unified CM) 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(1) allows remote attackers to cause a denial of service (service disruption) via a high rate of UDP packets, aka Bug ID CSCub85597.

    Published: 25 Aug 2013
    9.3
    Critical

    CVE-2013-5578

    Last Modified: 11 Apr 2025

    Buffer overflow in the ToDot method in the WINGRAPHVIZLib.NEATO ActiveX control in WinGraphviz.dll in StarUML allows remote attackers to execute arbitrary code via a long argument.

    Published: 25 Aug 2013
    7.5
    High

    CVE-2012-6584

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands via the bathrooms1 parameter to (1) demo2/search.php or (2) search.php.

    Published: 25 Aug 2013
    8.5
    High

    CVE-2013-3462

    Last Modified: 11 Apr 2025

    Buffer overflow in Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6, 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(2) allows remote authenticated users to execute arbitrary code via unspecified vectors, aka Bug ID CSCud54358.

    Published: 25 Aug 2013
    2.1
    Low

    CVE-2013-4216

    Last Modified: 11 Apr 2025

    The Trace_OpenLogFile function in InfraStack/OSDependent/Linux/InfraStackModules/TraceModule/TraceModule.c in the Trace module in the Intel WiMAX Network Service through 1.5.2 for Intel Wireless WiMAX Connection 2400 devices uses world-writable permissions for wimaxd.log, which allows local users to cause a denial of service (data corruption) by modifying this file.

    Published: 25 Aug 2013
    6.9
    Medium

    CVE-2013-1662

    Last Modified: 11 Apr 2025

    vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.

    Published: 24 Aug 2013
    6
    Medium

    CVE-2013-3369

    Last Modified: 11 Apr 2025

    Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote authenticated users with the permissions to view the administration pages to execute arbitrary private components via unspecified vectors.

    Published: 23 Aug 2013
    6.8
    Medium

    CVE-2013-3370

    Last Modified: 11 Apr 2025

    Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allows remote attackers to have an unspecified impact via a direct request.

    Published: 23 Aug 2013
    2.1
    Low

    CVE-2011-4607

    Last Modified: 11 Apr 2025

    PuTTY 0.59 through 0.61 does not clear sensitive process memory when managing user replies that occur during keyboard-interactive authentication, which might allow local users to read login passwords by obtaining access to the process' memory.

    Published: 23 Aug 2013
    7.5
    High

    CVE-2013-1434

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in (1) api_poller.php and (2) utility.php in Cacti before 0.8.8b allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 23 Aug 2013
    7.5
    High

    CVE-2013-1435

    Last Modified: 11 Apr 2025

    (1) snmp.php and (2) rrd.php in Cacti before 0.8.8b allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.

    Published: 23 Aug 2013
    3.3
    Low

    CVE-2013-3368

    Last Modified: 11 Apr 2025

    bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictable name.

    Published: 23 Aug 2013
    4.3
    Medium

    CVE-2013-3372

    Last Modified: 11 Apr 2025

    Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly conduct cross-site scripting (XSS) attacks via unspecified vectors.

    Published: 23 Aug 2013
    5
    Medium

    CVE-2013-3373

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header.

    Published: 23 Aug 2013