CVE Feed

    Dashboard / CVE

    5
    Medium

    CVE-2013-2981

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 17 Jun 2013
    4.3
    Medium

    CVE-2013-4608

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View & Descriptive Stats page.

    Published: 17 Jun 2013
    6.5
    Medium

    CVE-2013-4609

    Last Modified: 11 Apr 2025

    REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restrictions via (1) the Online Designer or (2) the Data Dictionary upload, as demonstrated by an eval call.

    Published: 17 Jun 2013
    10
    Critical

    CVE-2013-4610

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact and remote attack vectors.

    Published: 17 Jun 2013
    4.3
    Medium

    CVE-2013-4612

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in REDCap before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving different modules.

    Published: 17 Jun 2013
    4.3
    Medium

    CVE-2012-6564

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in REDCap before 4.14.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Jun 2013
    3.5
    Low

    CVE-2012-6565

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in REDCap before 4.14.3 allows remote authenticated users to inject arbitrary web script or HTML via uppercase characters in JavaScript events within user-defined labels.

    Published: 17 Jun 2013
    4.3
    Medium

    CVE-2012-6566

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in REDCap before 4.14.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 17 Jun 2013
    6.5
    Medium

    CVE-2012-6567

    Last Modified: 11 Apr 2025

    REDCap before 4.14.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the logic of a custom rule.

    Published: 17 Jun 2013
    5.8
    Medium

    CVE-2013-1093

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the fwdToURL function in the ZCC login page in zcc-framework.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the directToPage parameter.

    Published: 17 Jun 2013
    4.3
    Medium

    CVE-2013-1094

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a ZCC page in zenworks-core in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via an invalid locale.

    Published: 17 Jun 2013
    4.3
    Medium

    CVE-2013-1095

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError event.

    Published: 17 Jun 2013
    4.3
    Medium

    CVE-2013-1097

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in a ZCC page in njwc.jar in Novell ZENworks Configuration Management (ZCM) 11.2 before 11.2.3a Monthly Update 1 allows remote attackers to inject arbitrary web script or HTML via vectors involving an onload event.

    Published: 17 Jun 2013
    6.8
    Medium

    CVE-2013-2980

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Web Console in IBM Data Studio 3.1.0 and 3.1.1 allows remote attackers to hijack the authentication of arbitrary users for requests that access monitored database information.

    Published: 17 Jun 2013
    10
    Critical

    CVE-2013-4611

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Online Designer page or (2) the Manage Survey Participants page.

    Published: 17 Jun 2013
    4.3
    Medium

    CVE-2013-2309

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the management screen in OpenPNE 3.4.x before 3.4.21.1, 3.6.x before 3.6.9.1, and 3.8.x before 3.8.5.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving the "mobile version color scheme."

    Published: 17 Jun 2013
    9.3
    Critical

    CVE-2013-3026

    Last Modified: 11 Apr 2025

    Buffer overflow in the Lotus Quickr for Domino ActiveX control in qp2.cab in IBM Lotus Quickr 8.1 before FP 8.1.0.32-001a, 8.2 before FP 8.2.0.28-001a, and 8.5.1 before FP 8.5.1.39-002a for Domino allows remote attackers to execute arbitrary code via a crafted web site.

    Published: 17 Jun 2013
    7.5
    High

    CVE-2013-3520

    Last Modified: 11 Apr 2025

    VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors.

    Published: 17 Jun 2013
    4.3
    Medium

    CVE-2013-3642

    Last Modified: 11 Apr 2025

    The Angel Browser application 1.47b and earlier for Android 1.6 through 2.1, 1.62b and earlier for Android 2.2 through 2.3.4, 1.68b and earlier for Android 3.0 through 4.0.3, and 1.76b and earlier for Android 4.1 through 4.2 does not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.

    Published: 17 Jun 2013
    4.3
    Medium

    CVE-2013-3643

    Last Modified: 11 Apr 2025

    The Galapagos Browser application for Android does not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.

    Published: 17 Jun 2013
    3.3
    Low

    CVE-2013-2310

    Last Modified: 11 Apr 2025

    SoftBank Wi-Fi Spot Configuration Software, as used on SoftBank SHARP 3G handsets, SoftBank Panasonic 3G handsets, SoftBank NEC 3G handsets, SoftBank Samsung 3G handsets, SoftBank mobile Wi-Fi routers, SoftBank Android smartphones with the Wi-Fi application before 1.7.1, SoftBank Windows Mobile smartphones with the WISPrClient application before 1.3.1, SoftBank Disney Mobile Android smartphones with the Wi-Fi application before 1.7.1, and WILLCOM Android smartphones with the Wi-Fi application before 1.7.1, does not properly connect to access points, which allows remote attackers to obtain sensitive information by leveraging access to an 802.11 network.

    Published: 17 Jun 2013
    5
    Medium

    CVE-2013-2175

    Last Modified: 11 Apr 2025

    HAProxy 1.4 before 1.4.24 and 1.5 before 1.5-dev19, when configured to use hdr_ip or other "hdr_*" functions with a negative occurrence count, allows remote attackers to cause a denial of service (negative array index usage and crash) via an HTTP header with a certain number of values, related to the MAX_HDR_HISTORY variable.

    Published: 17 Jun 2013
    4.7
    Medium

    CVE-2013-2188

    Last Modified: 11 Apr 2025

    A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain write permissions, which allows local users to cause a denial of service (system crash) by leveraging access to a filesystem that is mounted read-only.

    Published: 17 Jun 2013
    7.1
    High

    CVE-2013-0148

    Last Modified: 11 Apr 2025

    The Data Camouflage (aka FairCom Standard Encryption) algorithm in FairCom c-treeACE does not ensure that a decryption key is needed for accessing database contents, which allows context-dependent attackers to read cleartext database records by copying a database to another system that has a certain default configuration.

    Published: 16 Jun 2013
    7.5
    High

    CVE-2013-3957

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 14 Jun 2013
    7.5
    High

    CVE-2013-3958

    Last Modified: 11 Apr 2025

    The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for remote attackers to obtain access via an unspecified request.

    Published: 14 Jun 2013
    4
    Medium

    CVE-2013-3959

    Last Modified: 11 Apr 2025

    The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the user account exists, which allows remote authenticated users to enumerate account names via crafted URL parameters.

    Published: 14 Jun 2013
    10
    Critical

    CVE-2013-2338

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on HP Integrated Lights-Out 3 (aka iLO3) cards with firmware before 1.57 and 4 (aka iLO4) cards with firmware before 1.22, when Single-Sign-On (SSO) is used, allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 14 Jun 2013
    7.1
    High

    CVE-2013-2783

    Last Modified: 11 Apr 2025

    The DNP3 driver in IOServer drivers 1.0.19.0 allows remote attackers to cause a denial of service (infinite loop) or obtain unspecified control via crafted data to TCP port 20000.

    Published: 14 Jun 2013
    5
    Medium

    CVE-2013-2336

    Last Modified: 11 Apr 2025

    HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to obtain sensitive information via unspecified vectors.

    Published: 14 Jun 2013
    4.3
    Medium

    CVE-2013-2337

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HP Service Manager 7.11, 9.21, 9.30, and 9.31, and ServiceCenter 6.2.8, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Jun 2013
    9
    Critical

    CVE-2013-3576

    Last Modified: 11 Apr 2025

    ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands via shell metacharacters in the PATH_INFO to smhutil/snmpchp.php.en.

    Published: 14 Jun 2013
    4.3
    Medium

    CVE-2013-3375

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the portal page in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCue23798.

    Published: 14 Jun 2013
    4.3
    Medium

    CVE-2013-3376

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490.

    Published: 14 Jun 2013
    10
    Critical

    CVE-2013-3573

    Last Modified: 11 Apr 2025

    HP Insight Diagnostics 9.4.0.4710 allows remote attackers to conduct unspecified injection attacks via unknown vectors.

    Published: 14 Jun 2013
    7.8
    High

    CVE-2013-3574

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount) parameter.

    Published: 14 Jun 2013
    5
    Medium

    CVE-2013-3575

    Last Modified: 11 Apr 2025

    hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows remote attackers to include arbitrary hpdiags/frontend2/help/ .html files via the path parameter.

    Published: 14 Jun 2013
    4.3
    Medium

    CVE-2013-3645

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Orchard.Comments module in Orchard before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 14 Jun 2013
    Unknown

    CVE-2013-1355

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate subsequently withdrew it. Notes: none

    Published: 13 Jun 2013
    4.3
    Medium

    CVE-2013-2157

    Last Modified: 11 Apr 2025

    OpenStack Keystone Folsom, Grizzly before 2013.1.3, and Havana, when using LDAP with Anonymous binding, allows remote attackers to bypass authentication via an empty password.

    Published: 13 Jun 2013
    7.5
    High

    CVE-2013-2161

    Last Modified: 11 Apr 2025

    XML injection vulnerability in account/utils.py in OpenStack Swift Folsom, Grizzly, and Havana allows attackers to trigger invalid or spoofed Swift responses via an account name.

    Published: 13 Jun 2013
    1.9
    Low

    CVE-2013-2168

    Last Modified: 11 Apr 2025

    The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.

    Published: 13 Jun 2013
    5.8
    Medium

    CVE-2013-1909

    Last Modified: 11 Apr 2025

    The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 13 Jun 2013
    4.3
    Medium

    CVE-2013-3970

    Last Modified: 11 Apr 2025

    Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 include a test Certification Authority (CA) certificate in the Trusted Server CAs list, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging control over that test CA.

    Published: 13 Jun 2013
    7.8
    High

    CVE-2013-1331

    Last Modified: 22 Apr 2026

    Buffer overflow in Microsoft Office 2003 SP3 and Office 2011 for Mac allows remote attackers to execute arbitrary code via crafted PNG data in an Office document, leading to improper memory allocation, aka "Office Buffer Overflow Vulnerability."

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3111

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3123.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3116

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 7 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3124

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3122.

    Published: 12 Jun 2013
    4.4
    Medium

    CVE-2013-3136

    Last Modified: 11 Apr 2025

    The kernel in Microsoft Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 on 32-bit platforms does not properly handle unspecified page-fault system calls, which allows local users to obtain sensitive information from kernel memory via a crafted application, aka "Kernel Information Disclosure Vulnerability."

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3110

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3141.

    Published: 12 Jun 2013