CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2013-2859

    Last Modified: 11 Apr 2025

    Google Chrome before 27.0.1453.110 allows remote attackers to bypass the Same Origin Policy and trigger namespace pollution via unspecified vectors.

    Published: 5 Jun 2013
    7.5
    High

    CVE-2013-2865

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.110 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 5 Jun 2013
    9.3
    Critical

    CVE-2013-2135

    Last Modified: 11 Apr 2025

    Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted value that contains both "${}" and "%{}" sequences, which causes the OGNL code to be evaluated twice.

    Published: 5 Jun 2013
    7.5
    High

    CVE-2013-2854

    Last Modified: 11 Apr 2025

    Google Chrome before 27.0.1453.110 on Windows provides an incorrect handle to a renderer process in unspecified circumstances, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 5 Jun 2013
    5
    Medium

    CVE-2013-2855

    Last Modified: 11 Apr 2025

    The Developer Tools API in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 5 Jun 2013
    7.5
    High

    CVE-2013-2856

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of input.

    Published: 5 Jun 2013
    7.5
    High

    CVE-2013-2860

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving access to a database API by a worker process.

    Published: 5 Jun 2013
    7.5
    High

    CVE-2013-2861

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 5 Jun 2013
    7.5
    High

    CVE-2013-2862

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 5 Jun 2013
    10
    Critical

    CVE-2013-2863

    Last Modified: 11 Apr 2025

    Google Chrome before 27.0.1453.110 does not properly handle SSL sockets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.

    Published: 5 Jun 2013
    7.5
    High

    CVE-2013-2864

    Last Modified: 11 Apr 2025

    The PDF functionality in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service (invalid free operation) or possibly have unspecified other impact via unknown vectors.

    Published: 5 Jun 2013
    9.3
    Critical

    CVE-2013-2134

    Last Modified: 11 Apr 2025

    Apache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is not properly handled during wildcard matching, a different vulnerability than CVE-2013-2135.

    Published: 5 Jun 2013
    3.8
    Low

    CVE-2013-2140

    Last Modified: 11 Apr 2025

    The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that supports the (1) BLKIF_OP_DISCARD (aka discard or TRIM) or (2) SCSI UNMAP feature.

    Published: 5 Jun 2013
    7.5
    High

    CVE-2013-2858

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the HTML5 Audio implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 5 Jun 2013
    7.8
    High

    CVE-2013-3919

    Last Modified: 11 Apr 2025

    resolver.c in ISC BIND 9.8.5 before 9.8.5-P1, 9.9.3 before 9.9.3-P1, and 9.6-ESV-R9 before 9.6-ESV-R9-P1, when a recursive resolver is configured, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query for a record in a malformed zone.

    Published: 4 Jun 2013
    5.8
    Medium

    CVE-2013-2316

    Last Modified: 11 Apr 2025

    The Yahoo! Browser application 1.4.4 and earlier for Android allows remote attackers to spoof the address bar via vectors related to URL display, a different vulnerability than CVE-2013-2307.

    Published: 3 Jun 2013
    5.8
    Medium

    CVE-2013-2317

    Last Modified: 11 Apr 2025

    The Sleipnir Mobile application 2.9.1 and earlier and Sleipnir Mobile Black Edition application 2.9.1 and earlier for Android allow remote attackers to spoof the address bar via vectors involving the opening of a new window.

    Published: 3 Jun 2013
    4.3
    Medium

    CVE-2013-0464

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM Eclipse Help System (IEHS) 3.4.3 and 3.6.2, as used in IBM SPSS Data Collection 6.0, 6.0.1, and 7.0, allow remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 3 Jun 2013
    6.5
    Medium

    CVE-2013-2970

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in IBM QRadar Security Information and Event Manager (SIEM) 7.x before 7.1 MR2 Patch 1 allows remote authenticated users to execute operating-system commands via unknown vectors.

    Published: 3 Jun 2013
    4.3
    Medium

    CVE-2013-0549

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Content Manager - Web Content Viewer Portlet in the server in IBM WebSphere Portal 7.0.0.x through 7.0.0.2 CF22 and 8.0.0.x through 8.0.0.1 CF5, when the IBM Portlet API is used, allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 3 Jun 2013
    3.5
    Low

    CVE-2013-2950

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in IBM WebSphere Portal 6.1.0.x before 6.1.0.3 CF26, 6.1.5.x before 6.1.5 CF26, 7.0.0.x before 7.0.0.2 CF21, and 8.0.0.x through 8.0.0.1 CF5, when home substitution (aka uri.home.substitution) is enabled, allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

    Published: 3 Jun 2013
    4.3
    Medium

    CVE-2013-2076

    Last Modified: 11 Apr 2025

    Xen 4.0.x, 4.1.x, and 4.2.x, when running on AMD64 processors, only save/restore the FOP, FIP, and FDP x87 registers in FXSAVE/FXRSTOR when an exception is pending, which allows one domain to determine portions of the state of floating point instructions of other domains, which can be leveraged to obtain sensitive information such as cryptographic keys, a similar vulnerability to CVE-2006-1056. NOTE: this is the documented behavior of AMD64 processors, but it is inconsistent with Intel processors in a security-relevant fashion that was not addressed by the kernels.

    Published: 3 Jun 2013
    2.1
    Low

    CVE-2013-2147

    Last Modified: 11 Apr 2025

    The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or (2) a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in drivers/block/cciss.c.

    Published: 3 Jun 2013
    4.7
    Medium

    CVE-2013-2078

    Last Modified: 11 Apr 2025

    Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.

    Published: 3 Jun 2013
    6.9
    Medium

    CVE-2013-2195

    Last Modified: 11 Apr 2025

    The Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "pointer dereferences" involving unexpected calculations.

    Published: 3 Jun 2013
    5.2
    Medium

    CVE-2013-2077

    Last Modified: 11 Apr 2025

    Xen 4.0.x, 4.1.x, and 4.2.x does not properly restrict the contents of a XRSTOR, which allows local PV guest users to cause a denial of service (unhandled exception and hypervisor crash) via unspecified vectors.

    Published: 3 Jun 2013
    2.1
    Low

    CVE-2013-2148

    Last Modified: 11 Apr 2025

    The fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a read operation on the fanotify descriptor.

    Published: 3 Jun 2013
    6.9
    Medium

    CVE-2013-2194

    Last Modified: 11 Apr 2025

    Multiple integer overflows in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel.

    Published: 3 Jun 2013
    6.9
    Medium

    CVE-2013-2196

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the Elf parser (libelf) in Xen 4.2.x and earlier allow local guest administrators with certain permissions to have an unspecified impact via a crafted kernel, related to "other problems" that are not CVE-2013-2194 or CVE-2013-2195.

    Published: 3 Jun 2013
    6.6
    Medium

    CVE-2013-3734

    Last Modified: 20 Apr 2025

    The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (1) man-in-the-middle attackers to obtain sensitive information by leveraging failure to use SSL or (2) attackers to obtain sensitive information by reading the HTML source code. NOTE: the vendor says that this does not cross a trust boundary and that it is recommended best-practice that SSL is configured for the administrative console

    Published: 2 Jun 2013
    6.8
    Medium

    CVE-2013-1633

    Last Modified: 11 Apr 2025

    easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product.

    Published: 2 Jun 2013
    4.3
    Medium

    CVE-2013-4488

    Last Modified: 12 Apr 2025

    libgadu before 1.12.0 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers.

    Published: 2 Jun 2013
    8.5
    High

    CVE-2013-0136

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation.

    Published: 1 Jun 2013
    4.3
    Medium

    CVE-2013-3261

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in wp-admin/admin.php in the GRAND FlAGallery plugin before 2.72 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter in a flag-manage-gallery action.

    Published: 1 Jun 2013
    4.3
    Medium

    CVE-2013-1247

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the wireless configuration module in Cisco Prime Infrastructure allows remote attackers to inject arbitrary web script or HTML via an SSID that is not properly handled during display of the XML windowing table, aka Bug ID CSCuf04356.

    Published: 31 May 2013
    6.5
    Medium

    CVE-2013-3315

    Last Modified: 11 Apr 2025

    The server in TIBCO Silver Mobile 1.1.0 does not properly verify access to the administrator role before executing a command, which allows authenticated users to gain privileges via unspecified vectors.

    Published: 31 May 2013
    6.8
    Medium

    CVE-2013-1246

    Last Modified: 11 Apr 2025

    Cisco TelePresence System Software does not properly handle inactive t-shell sessions, which allows remote authenticated users to cause a denial of service (memory consumption and service outage) by establishing multiple SSH connections, aka Bug ID CSCug77610.

    Published: 31 May 2013
    4.3
    Medium

    CVE-2013-3719

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the aiContactSafe component before 2.0.21 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 May 2013
    3.5
    Low

    CVE-2013-3720

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in widget_remove.php in the Feedweb plugin before 1.9 for WordPress allows remote authenticated administrators to inject arbitrary web script or HTML via the wp_post_id parameter.

    Published: 31 May 2013
    7.5
    High

    CVE-2013-3721

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in awards.php in PsychoStats 3.2.2b allows remote attackers to execute arbitrary SQL commands via the d parameter.

    Published: 31 May 2013
    7.8
    High

    CVE-2013-2112

    Last Modified: 11 Apr 2025

    The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.

    Published: 31 May 2013
    3.3
    Low

    CVE-2013-2142

    Last Modified: 11 Apr 2025

    userpref.c in libimobiledevice 1.1.4, when $HOME and $XDG_CONFIG_HOME are not set, allows local users to overwrite arbitrary files via a symlink attack on (1) HostCertificate.pem, (2) HostPrivateKey.pem, (3) libimobiledevicerc, (4) RootCertificate.pem, or (5) RootPrivateKey.pem in /tmp/root/.config/libimobiledevice/.

    Published: 31 May 2013
    7.8
    High

    CVE-2013-4247

    Last Modified: 11 Apr 2025

    Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in the Linux kernel before 3.9.6 allows remote attackers to cause a denial of service (memory corruption and system crash) via a DFS share mount operation that triggers use of an unexpected DFS referral name length.

    Published: 31 May 2013
    4.3
    Medium

    CVE-2013-2132

    Last Modified: 11 Apr 2025

    bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."

    Published: 31 May 2013
    6.4
    Medium

    CVE-2013-6408

    Last Modified: 11 Apr 2025

    The DocumentAnalysisRequestHandler in Apache Solr before 4.3.1 does not properly use the EmptyEntityResolver, which allows remote attackers to have an unspecified impact via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-6407.

    Published: 31 May 2013
    5.5
    Medium

    CVE-2013-1968

    Last Modified: 11 Apr 2025

    Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.

    Published: 31 May 2013
    7.1
    High

    CVE-2013-2088

    Last Modified: 11 Apr 2025

    contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.

    Published: 31 May 2013
    Unknown

    CVE-2013-3130

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3660, CVE-2013-3661. Reason: This candidate is a reservation duplicate of CVE-2013-3660 and CVE-2013-3661. Notes: All CVE users should reference CVE-2013-3660 and/or CVE-2013-3661 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 30 May 2013
    2.6
    Low

    CVE-2013-2139

    Last Modified: 11 Apr 2025

    Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and srtp_protect functions.

    Published: 30 May 2013
    5.5
    Medium

    CVE-2013-3718

    Last Modified: 21 Nov 2024

    evince is missing a check on number of pages which can lead to a segmentation fault

    Published: 30 May 2013