CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2013-1019

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.

    Published: 24 May 2013
    9.3
    Critical

    CVE-2013-1022

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted mvhd atoms in a movie file.

    Published: 24 May 2013
    9.3
    Critical

    CVE-2013-1021

    Last Modified: 11 Apr 2025

    Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG data in a movie file.

    Published: 24 May 2013
    7.5
    High

    CVE-2013-2126

    Last Modified: 11 Apr 2025

    Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-color (1) Foveon or (2) sRAW image file.

    Published: 24 May 2013
    4.9
    Medium

    CVE-2013-4220

    Last Modified: 11 Apr 2025

    The bad_mode function in arch/arm64/kernel/traps.c in the Linux kernel before 3.9.5 on the ARM64 platform allows local users to cause a denial of service (system crash) via vectors involving an attempted register access that triggers an unexpected value in the Exception Syndrome Register (ESR).

    Published: 24 May 2013
    5
    Medium

    CVE-2011-4518

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 23 May 2013
    4.3
    Medium

    CVE-2011-4519

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.

    Published: 23 May 2013
    4.3
    Medium

    CVE-2011-4520

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.

    Published: 23 May 2013
    10
    Critical

    CVE-2012-4697

    Last Modified: 11 Apr 2025

    TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to obtain administrative access via an FTP session.

    Published: 23 May 2013
    4.3
    Medium

    CVE-2012-6555

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the LatestComment plugin 1.1 for Vanilla Forums allows remote attackers to inject arbitrary web script or HTML via the discussion title.

    Published: 23 May 2013
    4.3
    Medium

    CVE-2012-6556

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the FirstLastNames plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) User/FirstName or (2) User/LastName parameter to the edit user page. NOTE: some of these details are obtained from third party information.

    Published: 23 May 2013
    9.3
    Critical

    CVE-2012-6558

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in HeavenTools PE Explorer 1.99 R6 allows remote attackers to execute arbitrary code via the size value for a string in the resource section of a Portable Executable (PE) file.

    Published: 23 May 2013
    4.3
    Medium

    CVE-2012-6559

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) mac, (3) graphtype, (4) name, or (5) type parameter to stats.php; or (6) comment parameter to deviceadd.php.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2012-6562

    Last Modified: 11 Apr 2025

    engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbitrary accounts.

    Published: 23 May 2013
    4.3
    Medium

    CVE-2012-6563

    Last Modified: 11 Apr 2025

    engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.

    Published: 23 May 2013
    9.3
    Critical

    CVE-2012-6553

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Resource Hacker 3.6.0.92 allows remote attackers to execute arbitrary code via a Portable Executable (PE) file with a resource section containing a string that has many tab or line feed characters.

    Published: 23 May 2013
    6.5
    Medium

    CVE-2012-6554

    Last Modified: 11 Apr 2025

    functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute arbitrary PHP code via the message[message_text] parameter to chat/add_messag, which is not properly handled when executing the preg_replace function with the eval switch.

    Published: 23 May 2013
    4.3
    Medium

    CVE-2012-6557

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attackers to inject arbitrary web script or HTML via the (1) AboutMe/RealName, (2) AboutMe/Name, (3) AboutMe/Quote, (4) AboutMe/Loc, (5) AboutMe/Emp, (6) AboutMe/JobTit, (7) AboutMe/HS, (8) AboutMe/Col, (9) AboutMe/Bio, (10) AboutMe/Inter, (11) AboutMe/Mus, (12) AboutMe/Gam, (13) AboutMe/Mov, (14) AboutMe/FTV, or (15) AboutMe/Bks parameter to the Edit My Details page. NOTE: some of these details are obtained from third party information.

    Published: 23 May 2013
    4.3
    Medium

    CVE-2012-6561

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the view parameter to index.php. NOTE: some of these details are obtained from third party information.

    Published: 23 May 2013
    7.5
    High

    CVE-2012-6560

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands via the status parameter.

    Published: 23 May 2013
    5
    Medium

    CVE-2013-1204

    Last Modified: 11 Apr 2025

    Memory leak in the SNMP process in Cisco IOS XR allows remote attackers to cause a denial of service (memory consumption or process reload) by sending many port-162 UDP packets, aka Bug ID CSCug80345.

    Published: 23 May 2013
    10
    Critical

    CVE-2013-2781

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1993

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libGLX in Mesa 9.1.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XF86DRIOpenConnection and (2) XF86DRIGetClientDriverName functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1996

    Last Modified: 11 Apr 2025

    X.org libFS 1.0.4 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the FSOpenServer function.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1999

    Last Modified: 11 Apr 2025

    Buffer overflow in X.org libXvMC 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvMCGetDRInfo function.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-2000

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in X.org libXxf86dga 1.1.3 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XDGAQueryModes and (2) XDGASetMode functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-2001

    Last Modified: 11 Apr 2025

    Buffer overflow in X.org libXxf86vm 1.1.2 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XF86VidModeGetGammaRamp function.

    Published: 23 May 2013
    7.2
    High

    CVE-2013-2069

    Last Modified: 11 Apr 2025

    Red Hat livecd-tools before 13.4.4, 17.x before 17.17, 18.x before 18.16, and 19.x before 19.3, when a rootpw directive is not set in a Kickstart file, sets the root user password to empty, which allows local users to gain privileges.

    Published: 23 May 2013
    7.5
    High

    CVE-2013-3735

    Last Modified: 11 Apr 2025

    The Zend Engine in PHP before 5.4.16 RC1, and 5.5.0 before RC2, does not properly determine whether a parser error occurred, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted function definition, as demonstrated by an attack within a shared web-hosting environment. NOTE: the vendor's http://php.net/security-note.php page says "for critical security situations you should be using OS-level security by running multiple web servers each as their own user id.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1982

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libXext 1.3.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XcupGetReservedColormapEntries, (2) XcupStoreColors, (3) XdbeGetVisualInfo, (4) XeviGetVisualInfo, (5) XShapeGetRectangles, and (6) XSyncListSystemCounters functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1983

    Last Modified: 11 Apr 2025

    Integer overflow in X.org libXfixes 5.0 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XFixesGetCursorImage function.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1984

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libXi 1.7.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XGetDeviceControl, (2) XGetFeedbackControl, (3) XGetDeviceDontPropagateList, (4) XGetDeviceMotionEvents, (5) XIGetProperty, (6) XIGetSelectedEvents, (7) XGetDeviceProperties, and (8) XListInputDevices functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1985

    Last Modified: 11 Apr 2025

    Integer overflow in X.org libXinerama 1.1.2 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XineramaQueryScreens function.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1988

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libXRes 1.0.6 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XResQueryClients and (2) XResQueryClientResources functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1989

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libXv 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XvQueryPortAttributes, (2) XvListImageFormats, and (3) XvCreateImage function.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1990

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libXvMC 1.0.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XvMCListSurfaceTypes and (2) XvMCListSubpictureTypes functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1991

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libXxf86dga 1.1.3 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XDGAQueryModes and (2) XDGASetMode functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1992

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libdmx 1.1.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) DMXGetScreenAttributes, (2) DMXGetWindowAttributes, and (3) DMXGetInputAttributes functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1995

    Last Modified: 11 Apr 2025

    X.org libXi 1.7.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to an unexpected sign extension in the XListInputDevices function.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1998

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in X.org libXi 1.7.1 and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XGetDeviceButtonMapping, (2) XIPassiveGrabDevice, and (3) XQueryDeviceState functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-2002

    Last Modified: 11 Apr 2025

    Buffer overflow in X.org libXt 1.1.3 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the _XtResourceConfigurationEH function.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-2003

    Last Modified: 11 Apr 2025

    Integer overflow in X.org libXcursor 1.1.13 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the _XcursorFileHeaderCreate function.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-2064

    Last Modified: 11 Apr 2025

    Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-2066

    Last Modified: 11 Apr 2025

    Buffer overflow in X.org libXv 1.0.7 and earlier allows X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the XvQueryPortAttributes function.

    Published: 23 May 2013
    4.3
    Medium

    CVE-2013-1896

    Last Modified: 11 Apr 2025

    mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1981

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XQueryFont, (2) _XF86BigfontQueryFont, (3) XListFontsWithInfo, (4) XGetMotionEvents, (5) XListHosts, (6) XGetModifierMapping, (7) XGetPointerMapping, (8) XGetKeyboardMapping, (9) XGetWindowProperty, (10) XGetImage, (11) LoadColornameDB, (12) XrmGetFileDatabase, (13) _XimParseStringFile, or (14) TransFileName functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1986

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libXrandr 1.4.0 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRRQueryOutputProperty and (2) XRRQueryProviderProperty functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1987

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRenderQueryFilters, (2) XRenderQueryFormats, and (3) XRenderQueryPictIndexValues functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1994

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libchromeXvMC and libchromeXvMCPro in openChrome 0.3.2 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) uniDRIOpenConnection and (2) uniDRIGetClientDriverName functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-1997

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in X.org libX11 1.5.99.901 (1.6 RC1) and earlier allow X servers to cause a denial of service (crash) and possibly execute arbitrary code via crafted length or index values to the (1) XAllocColorCells, (2) _XkbReadGetDeviceInfoReply, (3) _XkbReadGeomShapes, (4) _XkbReadGetGeometryReply, (5) _XkbReadKeySyms, (6) _XkbReadKeyActions, (7) _XkbReadKeyBehaviors, (8) _XkbReadModifierMap, (9) _XkbReadExplicitComponents, (10) _XkbReadVirtualModMap, (11) _XkbReadGetNamesReply, (12) _XkbReadGetMapReply, (13) _XimXGetReadData, (14) XListFonts, (15) XListExtensions, and (16) XGetFontPath functions.

    Published: 23 May 2013