CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-1972

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors.

    Published: 24 Jun 2013
    4.3
    Medium

    CVE-2013-2129

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Webform module 6.x-3.x before 6.x-3.19 for Drupal allows remote authenticated users with the "edit own webform content" or "edit all webform content" permissions to inject arbitrary web script or HTML via a component label.

    Published: 24 Jun 2013
    4.3
    Medium

    CVE-2013-1906

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Rules module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with the "administer rules" permission to inject arbitrary web script or HTML via a rule tag.

    Published: 24 Jun 2013
    5.3
    Medium

    CVE-2013-7491

    Last Modified: 21 Nov 2024

    An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack gets reallocated.

    Published: 24 Jun 2013
    6.8
    Medium

    CVE-2013-2174

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string ending in a "%" (percent) character.

    Published: 22 Jun 2013
    7.5
    High

    CVE-2013-4613

    Last Modified: 11 Apr 2025

    The default configuration of the administrative interface on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers does not require authentication, which allows remote attackers to modify the configuration by visiting the Advanced page. NOTE: the vendor has apparently responded by stating "for user convenience, the default setting does not require a password. However, if a user has a particular concern about third parties accessing the user's home printer, the default setting can be changed to add a password."

    Published: 21 Jun 2013
    4.3
    Medium

    CVE-2013-3392

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in Cisco WebEx Social allow remote attackers to hijack the authentication of arbitrary users via unspecified vectors, aka Bug IDs CSCuh10405 and CSCuh10355.

    Published: 21 Jun 2013
    2.1
    Low

    CVE-2013-4614

    Last Modified: 11 Apr 2025

    English/pages_MacUS/wls_set_content.html on the Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers shows the Wi-Fi PSK passphrase in cleartext, which allows physically proximate attackers to obtain sensitive information by reading the screen of an unattended workstation.

    Published: 21 Jun 2013
    5
    Medium

    CVE-2013-4615

    Last Modified: 11 Apr 2025

    The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of service (device hang) via a crafted LAN_TXT24 parameter to English/pages_MacUS/cgi_lan.cgi followed by a direct request to English/pages_MacUS/lan_set_content.html. NOTE: the vendor has apparently responded by stating "Canon believes that its printers will not have to deal with unauthorized access to the network from an external location as long as the printers are used in a secured environment."

    Published: 21 Jun 2013
    6.8
    Medium

    CVE-2013-3250

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the WP Maintenance Mode plugin before 1.8.8 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that modify this plugin's settings.

    Published: 21 Jun 2013
    4.3
    Medium

    CVE-2012-6572

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the phptemplate_preprocess_node function in template.php in the Inf08 theme 6.x-1.x before 6.x-1.10 for Drupal allows remote authenticated users with the "administer taxonomy" permission to inject arbitrary web script or HTML via a taxonomy vocabulary name.

    Published: 21 Jun 2013
    4.3
    Medium

    CVE-2013-0523

    Last Modified: 11 Apr 2025

    IBM WebSphere Commerce Enterprise 5.6.x through 5.6.1.5, 6.0.x through 6.0.0.11, and 7.0.x through 7.0.0.7 does not use a suitable encryption algorithm for storefront web requests, which allows remote attackers to obtain sensitive information via a padding oracle attack that targets certain UTF-8 processing of the krypto parameter, and leverages unspecified browser access or traffic-log access.

    Published: 21 Jun 2013
    5
    Medium

    CVE-2013-0551

    Last Modified: 11 Apr 2025

    The Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to cause a denial of service (abend) via a crafted URL.

    Published: 21 Jun 2013
    5
    Medium

    CVE-2013-2960

    Last Modified: 11 Apr 2025

    Buffer overflow in KDSMAIN in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to cause a denial of service (segmentation fault) via a crafted http URL.

    Published: 21 Jun 2013
    7.2
    High

    CVE-2013-0536

    Last Modified: 11 Apr 2025

    ntmulti.exe in the Multi User Profile Cleanup service in IBM Notes 8.0, 8.0.1, 8.0.2, 8.5, 8.5.1, 8.5.2, 8.5.3 before FP5, and 9.0 before IF2 allows local users to gain privileges via vectors that arrange for code to be executed during the next login session of a different user, aka SPR PJOK959J24.

    Published: 21 Jun 2013
    4.3
    Medium

    CVE-2013-0548

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Jun 2013
    4.3
    Medium

    CVE-2013-2961

    Last Modified: 11 Apr 2025

    The internal web server in the Basic Services component in IBM Tivoli Monitoring (ITM) 6.2.0 through FP3, 6.2.1 through FP4, 6.2.2 through FP9, and 6.2.3 before FP3, as used in IBM Application Manager for Smart Business (formerly Tivoli Foundations Application Manager) 1.2.1 before 1.2.1.0-TIV-IAMSB-FP0004 and other products, allows remote attackers to perform unspecified redirection of HTTP requests, and bypass the proxy-server configuration, via crafted HTTP traffic.

    Published: 21 Jun 2013
    1.9
    Low

    CVE-2013-0527

    Last Modified: 11 Apr 2025

    The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not close pages upon the timeout of a session, which allows physically proximate attackers to obtain sensitive administrative-console information by reading the screen of an unattended workstation.

    Published: 21 Jun 2013
    1.9
    Low

    CVE-2013-0534

    Last Modified: 11 Apr 2025

    The Connect client in IBM Sametime 8.5.1, 8.5.1.1, 8.5.1.2, 8.5.2, and 8.5.2.1, as used in the Lotus Notes client and separately, might allow local users to obtain sensitive information by leveraging the persistence of cleartext password strings within process memory.

    Published: 21 Jun 2013
    7.1
    High

    CVE-2013-3035

    Last Modified: 11 Apr 2025

    The IPv6 implementation in the inet subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allows remote attackers to cause a denial of service (system hang) via a crafted packet to an IPv6 interface.

    Published: 21 Jun 2013
    5
    Medium

    CVE-2013-0529

    Last Modified: 11 Apr 2025

    The Browser in IBM Sterling Connect:Direct 1.4 before 1.4.0.11 and 1.5 through 1.5.0.1 does not set the secure flag for the session cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session.

    Published: 21 Jun 2013
    7.8
    High

    CVE-2013-3378

    Last Modified: 11 Apr 2025

    Cisco TelePresence TC Software before 6.1 and TE Software before 4.1.3 allow remote attackers to cause a denial of service (temporary device hang) via crafted SIP packets, aka Bug ID CSCuf89557.

    Published: 21 Jun 2013
    4.3
    Medium

    CVE-2013-2173

    Last Modified: 11 Apr 2025

    wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.

    Published: 21 Jun 2013
    7.8
    High

    CVE-2013-3377

    Last Modified: 11 Apr 2025

    Cisco TelePresence TC Software before 5.1.7 and TE Software before 4.1.3 allow remote attackers to cause a denial of service (device reload) via crafted SIP packets, aka Bug ID CSCue01743.

    Published: 21 Jun 2013
    8.3
    High

    CVE-2013-3379

    Last Modified: 11 Apr 2025

    The firewall subsystem in Cisco TelePresence TC Software before 4.2 does not properly implement rules that grant access to hosts, which allows remote attackers to obtain shell access with root privileges by leveraging connectivity to the management network, aka Bug ID CSCts37781.

    Published: 21 Jun 2013
    3.5
    Low

    CVE-2013-1417

    Last Modified: 11 Apr 2025

    do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) 1.11 before 1.11.4, when a single-component realm name is used, allows remote authenticated users to cause a denial of service (daemon crash) via a TGS-REQ request that triggers an attempted cross-realm referral for a host-based service principal.

    Published: 21 Jun 2013
    4.3
    Medium

    CVE-2013-1905

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Zero Point theme 7.x-1.x before 7.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Jun 2013
    7.5
    High

    CVE-2013-4634

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the jQuery autocomplete for indexed_search (rzautocomplete) extension before 0.0.9 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 20 Jun 2013
    2.1
    Low

    CVE-2013-1393

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the CurvyCorners module 6.x-1.x and 7.x-1.x for Drupal allows remote authenticated users with the "administer curvycorners" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 20 Jun 2013
    6.9
    Medium

    CVE-2012-6568

    Last Modified: 11 Apr 2025

    Buffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN_NAME string in a plug-in configuration file.

    Published: 20 Jun 2013
    3.5
    Low

    CVE-2013-4628

    Last Modified: 11 Apr 2025

    The firewall module on the Huawei Quidway Service Process Unit (SPU) board S7700, S9300, and S9700 on Huawei Campus Switch devices allows remote authenticated users to obtain sensitive information from the high-priority security zone by leveraging access to the low-priority security zone.

    Published: 20 Jun 2013
    8.5
    High

    CVE-2013-4629

    Last Modified: 11 Apr 2025

    The Huawei viewpoint VP9610 and VP9620 units for the Huawei Video Conference system do not update the Session ID upon successful establishment of a login session, which allows remote authenticated users to hijack sessions via an unspecified interception method.

    Published: 20 Jun 2013
    7.6
    High

    CVE-2013-4630

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers to execute arbitrary code via malformed SNMPv3 requests.

    Published: 20 Jun 2013
    7.8
    High

    CVE-2013-4631

    Last Modified: 11 Apr 2025

    Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 is enabled, allow remote attackers to cause a denial of service (device crash) via malformed SNMPv3 requests that leverage unspecified overflow issues.

    Published: 20 Jun 2013
    9
    Critical

    CVE-2013-4633

    Last Modified: 11 Apr 2025

    Huawei Seco Versatile Security Manager (VSM) before V200R002C00SPC300 allows remote authenticated users to gain privileges via a certain change to a group configuration setting.

    Published: 20 Jun 2013
    6.5
    Medium

    CVE-2012-4960

    Last Modified: 11 Apr 2025

    The Huawei NE5000E, MA5200G, NE40E, NE80E, ATN, NE40, NE80, NE20E-X6, NE20, ME60, CX600, CX200, CX300, ACU, WLAN AC 6605, S9300, S7700, S2300, S3300, S5300, S3300HI, S5300HI, S5306, S6300, S2700, S3700, S5700, S6700, AR G3, H3C AR(OEM IN), AR 19, AR 29, AR 49, Eudemon100E, Eudemon200, Eudemon300, Eudemon500, Eudemon1000, Eudemon1000E-U/USG5300, Eudemon1000E-X/USG5500, Eudemon8080E/USG9300, Eudemon8160E/USG9300, Eudemon8000E-X/USG9500, E200E-C/USG2200, E200E-X3/USG2200, E200E-X5/USG2200, E200E-X7/USG2200, E200E-C/USG5100, E200E-X3/USG5100, E200E-X5/USG5100, E200E-X7/USG5100, E200E-B/USG2100, E200E-X1/USG2100, E200E-X2/USG2100, SVN5300, SVN2000, SVN5000, SVN3000, NIP100, NIP200, NIP1000, NIP2100, NIP2200, and NIP5100 use the DES algorithm for stored passwords, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

    Published: 20 Jun 2013
    9.3
    Critical

    CVE-2012-6569

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches allows remote attackers to execute arbitrary code via a long URI.

    Published: 20 Jun 2013
    7.5
    High

    CVE-2012-6571

    Last Modified: 11 Apr 2025

    The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, and S7800 switches uses predictable Session ID values, which makes it easier for remote attackers to hijack sessions via a brute-force attack.

    Published: 20 Jun 2013
    7.8
    High

    CVE-2013-4632

    Last Modified: 11 Apr 2025

    The Huawei Access Router (AR) before V200R002SPC003 allows remote attackers to cause a denial of service (device reset) via a crafted field in a DHCP request, as demonstrated by a request from an IP phone.

    Published: 20 Jun 2013
    10
    Critical

    CVE-2012-6570

    Last Modified: 11 Apr 2025

    The HTTP module in the (1) Branch Intelligent Management System (BIMS) and (2) web management components on Huawei AR routers and S2000, S3000, S3500, S3900, S5100, S5600, S7800, and S8500 switches does not check whether HTTP data is longer than the value of the Content-Length field, which allows remote HTTP servers to conduct heap-based buffer overflow attacks and execute arbitrary code via a crafted response.

    Published: 20 Jun 2013
    7.9
    High

    CVE-2013-1612

    Last Modified: 11 Apr 2025

    Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.1.3, and Symantec Endpoint Protection Center (SPC) Small Business Edition 12.0.x, allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 20 Jun 2013
    4.4
    Medium

    CVE-2013-4136

    Last Modified: 11 Apr 2025

    ext/common/ServerInstanceDir.h in Phusion Passenger gem before 4.0.6 for Ruby allows local users to gain privileges or possibly change the ownership of arbitrary directories via a symlink attack on a directory with a predictable name in /tmp/.

    Published: 20 Jun 2013
    5
    Medium

    CVE-2013-4160

    Last Modified: 11 Apr 2025

    Little CMS (lcms2) before 2.5, as used in OpenJDK 7 and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to (1) cmsStageAllocLabV2ToV4curves, (2) cmsPipelineDup, (3) cmsAllocProfileSequenceDescription, (4) CurvesAlloc, and (5) cmsnamed.

    Published: 20 Jun 2013
    7.4
    High

    CVE-2013-2211

    Last Modified: 11 Apr 2025

    The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspecified vectors.

    Published: 20 Jun 2013
    4.3
    Medium

    CVE-2013-2866

    Last Modified: 11 Apr 2025

    The Flash plug-in in Google Chrome before 27.0.1453.116, as used on Google Chrome OS before 27.0.1453.116 and separately, does not properly determine whether a user wishes to permit camera or microphone access by a Flash application, which allows remote attackers to obtain sensitive information from a machine's physical environment via a clickjacking attack, as demonstrated by an attack using a crafted Cascading Style Sheets (CSS) opacity property.

    Published: 19 Jun 2013
    6.3
    Medium

    CVE-2013-2968

    Last Modified: 11 Apr 2025

    An unspecified buffer-read method in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to cause a denial of service via a large file that lacks end-of-line characters.

    Published: 19 Jun 2013
    3.5
    Low

    CVE-2013-2969

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Sterling Control Center (SCC) 5.2 before 5.2.0.9, 5.3 before 5.3.0.4, and 5.4 through 5.4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors involving invalid characters.

    Published: 19 Jun 2013
    4.3
    Medium

    CVE-2013-0484

    Last Modified: 11 Apr 2025

    The server process in IBM Cognos TM1 10.1.x before 10.1.1 FP1 allows remote attackers to cause a denial of service (daemon crash) via an undocumented API call that triggers the transmission of unexpected data.

    Published: 19 Jun 2013
    7.5
    High

    CVE-2013-4622

    Last Modified: 11 Apr 2025

    The 3G Mobile Hotspot feature on the HTC Droid Incredible has a default WPA2 PSK passphrase of 1234567890, which makes it easier for remote attackers to obtain access by leveraging a position within the WLAN coverage area.

    Published: 19 Jun 2013
    9.8
    Critical

    CVE-2013-2166

    Last Modified: 21 Nov 2024

    python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass

    Published: 19 Jun 2013