CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2013-3113

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3114

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3119.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3118

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3120 and CVE-2013-3125.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3119

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3114.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3120

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3125.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3121

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3139, and CVE-2013-3142.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3122

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3117 and CVE-2013-3124.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3123

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3111.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3126

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 and 10, when script debugging is enabled, does not properly handle objects in memory during the processing of script, which allows remote attackers to execute arbitrary code via a crafted web site, aka "Internet Explorer Script Debug Vulnerability."

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3139

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3142.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3141

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3110.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3142

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3112, CVE-2013-3113, CVE-2013-3121, and CVE-2013-3139.

    Published: 12 Jun 2013
    4
    Medium

    CVE-2013-3380

    Last Modified: 11 Apr 2025

    The administrative web interface in the Access Control Server in Cisco Secure Access Control System (ACS) does not properly restrict the report view page, which allows remote authenticated users to obtain sensitive information via a direct request, aka Bug ID CSCue79279.

    Published: 12 Jun 2013
    5
    Medium

    CVE-2013-3381

    Last Modified: 11 Apr 2025

    Cisco Hosted Collaboration Mediation allows remote attackers to cause a denial of service (CPU consumption) via a flood of malformed UDP packets on port 162, aka Bug ID CSCug85756.

    Published: 12 Jun 2013
    9
    Critical

    CVE-2013-1339

    Last Modified: 11 Apr 2025

    The Print Spooler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly manage memory during deletion of printer connections, which allows remote authenticated users to execute arbitrary code via a crafted request, aka "Print Spooler Vulnerability."

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3112

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3113, CVE-2013-3121, CVE-2013-3139, and CVE-2013-3142.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3117

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3122 and CVE-2013-3124.

    Published: 12 Jun 2013
    9.3
    Critical

    CVE-2013-3125

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3120.

    Published: 12 Jun 2013
    7.1
    High

    CVE-2013-3138

    Last Modified: 11 Apr 2025

    Integer overflow in the TCP/IP kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (system hang) via crafted TCP packets, aka "TCP/IP Integer Overflow Vulnerability."

    Published: 12 Jun 2013
    0
    Low

    CVE-2013-4186

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

    Published: 12 Jun 2013
    7.5
    High

    CVE-2013-1768

    Last Modified: 11 Apr 2025

    The BrokerFactory functionality in Apache OpenJPA 1.x before 1.2.3 and 2.x before 2.2.2 creates local executable JSP files containing logging trace data produced during deserialization of certain crafted OpenJPA objects, which makes it easier for remote attackers to execute arbitrary code by creating a serialized object and leveraging improperly secured server programs.

    Published: 12 Jun 2013
    10
    Critical

    CVE-2013-3343

    Last Modified: 11 Apr 2025

    Adobe Flash Player before 10.3.183.90 and 11.x before 11.7.700.224 on Windows, before 10.3.183.90 and 11.x before 11.7.700.225 on Mac OS X, before 10.3.183.90 and 11.x before 11.2.202.291 on Linux, before 11.1.111.59 on Android 2.x and 3.x, and before 11.1.115.63 on Android 4.x; Adobe AIR before 3.7.0.2090 on Windows and Android and before 3.7.0.2100 on Mac OS X; and Adobe AIR SDK & Compiler before 3.7.0.2090 on Windows and before 3.7.0.2100 on Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 11 Jun 2013
    4.3
    Medium

    CVE-2013-2179

    Last Modified: 11 Apr 2025

    X.Org xdm 1.1.10, 1.1.11, and possibly other versions, when performing authentication using certain implementations of the crypt API function that can return NULL, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) by attempting to log into an account whose password field contains invalid characters, as demonstrated using the crypt function from glibc 2.17 and later with (1) the "!" character in the salt portion of a password field or (2) a password that has been encrypted using DES or MD5 in FIPS-140 mode.

    Published: 11 Jun 2013
    5.8
    Medium

    CVE-2013-2319

    Last Modified: 11 Apr 2025

    FileMaker Pro before 12 and Pro Advanced before 12 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 10 Jun 2013
    4.3
    Medium

    CVE-2013-3640

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Instant Web Publish function in FileMaker Pro before 12 and Pro Advanced before 12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 10 Jun 2013
    5.8
    Medium

    CVE-2013-3641

    Last Modified: 11 Apr 2025

    The Pizza Hut Japan Official Order application before 1.1.1.a for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 10 Jun 2013
    4.3
    Medium

    CVE-2013-3670

    Last Modified: 11 Apr 2025

    The rle_unpack function in vmdav.c in libavcodec in FFmpeg git 20130328 through 20130501 does not properly use the bytestream2 API, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted RLE data. NOTE: the vendor has listed this as an issue fixed in 1.2.1, but the issue is actually in new code that was not shipped with the 1.2.1 release or any earlier release.

    Published: 10 Jun 2013
    4.3
    Medium

    CVE-2013-3671

    Last Modified: 11 Apr 2025

    The format_line function in log.c in libavutil in FFmpeg before 1.2.1 uses inapplicable offset data during a certain category calculation, which allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via crafted data that triggers a log message.

    Published: 10 Jun 2013
    4.3
    Medium

    CVE-2013-3672

    Last Modified: 11 Apr 2025

    The mm_decode_inter function in mmvideo.c in libavcodec in FFmpeg before 1.2.1 does not validate the relationship between a horizontal coordinate and a width value, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted American Laser Games (ALG) MM Video data.

    Published: 10 Jun 2013
    4.3
    Medium

    CVE-2013-3673

    Last Modified: 11 Apr 2025

    The gif_decode_frame function in gifdec.c in libavcodec in FFmpeg before 1.2.1 does not properly manage the disposal methods of frames, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted GIF data.

    Published: 10 Jun 2013
    4.3
    Medium

    CVE-2013-3674

    Last Modified: 11 Apr 2025

    The cdg_decode_frame function in cdgraphics.c in libavcodec in FFmpeg before 1.2.1 does not validate the presence of non-header data in a buffer, which allows remote attackers to cause a denial of service (out-of-bounds array access and application crash) via crafted CD Graphics Video data.

    Published: 10 Jun 2013
    4.3
    Medium

    CVE-2013-3675

    Last Modified: 11 Apr 2025

    The process_frame_obj function in sanm.c in libavcodec in FFmpeg before 1.2.1 does not validate width and height values, which allows remote attackers to cause a denial of service (integer overflow, out-of-bounds array access, and application crash) via crafted LucasArts Smush video data.

    Published: 10 Jun 2013
    5
    Medium

    CVE-2013-2144

    Last Modified: 11 Apr 2025

    Red Hat Enterprise Virtualization Manager (RHEVM) before 3.2 does not properly check permissions for the target storage domain, which allows attackers to cause a denial of service (disk space consumption) by cloning a VM from a snapshot.

    Published: 10 Jun 2013
    5.7
    Medium

    CVE-2013-1935

    Last Modified: 11 Apr 2025

    A certain Red Hat patch to the KVM subsystem in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly implement the PV EOI feature, which allows guest OS users to cause a denial of service (host OS crash) by leveraging a time window during which interrupts are disabled but copy_to_user function calls are possible.

    Published: 10 Jun 2013
    7.2
    High

    CVE-2013-2151

    Last Modified: 11 Apr 2025

    Unquoted Windows search path vulnerability in Red Hat Enterprise Virtualization (RHEV) 3 and 3.2 allows local users to gain privileges via a crafted application in an unspecified folder.

    Published: 10 Jun 2013
    7.2
    High

    CVE-2013-2152

    Last Modified: 11 Apr 2025

    Unquoted Windows search path vulnerability in the SPICE service, as used in Red Hat Enterprise Virtualization (RHEV) 3.2, allows local users to gain privileges via a crafted application in an unspecified folder.

    Published: 10 Jun 2013
    2.7
    Low

    CVE-2013-0167

    Last Modified: 11 Apr 2025

    VDSM in Red Hat Enterprise Virtualization 3 and 3.2 allows privileged guest users to cause the host to become "unavailable to the managment server" via guestInfo dictionaries with "unexpected fields."

    Published: 10 Jun 2013
    7.8
    High

    CVE-2013-1943

    Last Modified: 11 Apr 2025

    The KVM subsystem in the Linux kernel before 3.0 does not check whether kernel addresses are specified during allocation of memory slots for use in a guest's physical address space, which allows local users to gain privileges or obtain sensitive information from kernel memory via a crafted application, related to arch/x86/kvm/paging_tmpl.h and virt/kvm/kvm_main.c.

    Published: 10 Jun 2013
    6.8
    Medium

    CVE-2014-9622

    Last Modified: 12 Apr 2025

    Eval injection vulnerability in xdg-utils 1.1.0 RC1, when no supported desktop environment is identified, allows context-dependent attackers to execute arbitrary code via the URL argument to xdg-open.

    Published: 10 Jun 2013
    9.8
    Critical

    CVE-2011-1180

    Last Modified: 11 Apr 2025

    Multiple stack-based buffer overflows in the iriap_getvaluebyclass_indication function in net/irda/iriap.c in the Linux kernel before 2.6.39 allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging connectivity to an IrDA infrared network and sending a large integer value for a (1) name length or (2) attribute length.

    Published: 8 Jun 2013
    4.6
    Medium

    CVE-2011-3619

    Last Modified: 11 Apr 2025

    The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 3.0 does not properly handle invalid parameters, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact by writing to a /proc/#####/attr/current file.

    Published: 8 Jun 2013
    7.5
    High

    CVE-2011-4087

    Last Modified: 11 Apr 2025

    The br_parse_ip_options function in net/bridge/br_netfilter.c in the Linux kernel before 2.6.39 does not properly initialize a certain data structure, which allows remote attackers to cause a denial of service by leveraging connectivity to a network interface that uses an Ethernet bridge device.

    Published: 8 Jun 2013
    1.9
    Low

    CVE-2011-4098

    Last Modified: 11 Apr 2025

    The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3.2 relies on the page cache, which might allow local users to cause a denial of service by preallocating blocks in certain situations involving insufficient memory.

    Published: 8 Jun 2013
    5
    Medium

    CVE-2013-0142

    Last Modified: 11 Apr 2025

    QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access via unspecified vectors.

    Published: 7 Jun 2013
    6.5
    Medium

    CVE-2013-0143

    Last Modified: 11 Apr 2025

    cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.

    Published: 7 Jun 2013
    2.1
    Low

    CVE-2013-0947

    Last Modified: 11 Apr 2025

    EMC RSA Authentication Manager 8.0 before P1 allows local users to discover cleartext operating-system passwords, HTTP plug-in proxy passwords, and SNMP communities by reading a (1) log file or (2) configuration file.

    Published: 7 Jun 2013
    6.8
    Medium

    CVE-2013-0144

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in cgi-bin/create_user.cgi on QNAP VioStor NVR devices with firmware 4.0.3 allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts via a NEW USER action.

    Published: 7 Jun 2013
    5
    Medium

    CVE-2013-4074

    Last Modified: 11 Apr 2025

    The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 7 Jun 2013
    5
    Medium

    CVE-2013-4076

    Last Modified: 11 Apr 2025

    Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Published: 7 Jun 2013
    5
    Medium

    CVE-2013-4077

    Last Modified: 11 Apr 2025

    Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to nbap.cnf and packet-nbap.c.

    Published: 7 Jun 2013