CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2013-2004

    Last Modified: 11 Apr 2025

    The (1) GetDatabase and (2) _XimParseStringFile functions in X.org libX11 1.5.99.901 (1.6 RC1) and earlier do not restrict the recursion depth when processing directives to include files, which allows X servers to cause a denial of service (stack consumption) via a crafted file.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-2005

    Last Modified: 11 Apr 2025

    X.org libXt 1.1.3 and earlier does not check the return value of the XGetWindowProperty function, which allows X servers to trigger use of an uninitialized pointer and memory corruption via vectors related to the (1) ReqCleanup, (2) HandleSelectionEvents, (3) ReqTimedOut, (4) HandleNormal, and (5) HandleSelectionReplies functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-2062

    Last Modified: 11 Apr 2025

    Multiple integer overflows in X.org libXp 1.0.1 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XpGetAttributes, (2) XpGetOneAttribute, (3) XpGetPrinterList, and (4) XpQueryScreens functions.

    Published: 23 May 2013
    6.8
    Medium

    CVE-2013-2063

    Last Modified: 11 Apr 2025

    Integer overflow in X.org libXtst 1.2.1 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the XRecordGetContext function.

    Published: 23 May 2013
    7.5
    High

    CVE-2013-2844

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the Cascading Style Sheets (CSS) implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to style resolution.

    Published: 22 May 2013
    5
    Medium

    CVE-2013-2848

    Last Modified: 11 Apr 2025

    The XSS Auditor in Google Chrome before 27.0.1453.93 might allow remote attackers to obtain sensitive information via unspecified vectors.

    Published: 22 May 2013
    4.3
    Medium

    CVE-2013-2311

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 May 2013
    7.5
    High

    CVE-2013-2836

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in Google Chrome before 27.0.1453.93 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 22 May 2013
    7.5
    High

    CVE-2013-2837

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 22 May 2013
    5
    Medium

    CVE-2013-2838

    Last Modified: 11 Apr 2025

    Google V8, as used in Google Chrome before 27.0.1453.93, allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 22 May 2013
    7.5
    High

    CVE-2013-2839

    Last Modified: 11 Apr 2025

    Google Chrome before 27.0.1453.93 does not properly perform a cast of an unspecified variable during handling of clipboard data, which allows remote attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 22 May 2013
    7.5
    High

    CVE-2013-2840

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2846.

    Published: 22 May 2013
    7.5
    High

    CVE-2013-2841

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of Pepper resources.

    Published: 22 May 2013
    7.5
    High

    CVE-2013-2842

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets.

    Published: 22 May 2013
    7.5
    High

    CVE-2013-2843

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of speech data.

    Published: 22 May 2013
    7.5
    High

    CVE-2013-2845

    Last Modified: 11 Apr 2025

    The Web Audio implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 22 May 2013
    7.5
    High

    CVE-2013-2846

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the media loader in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2013-2840.

    Published: 22 May 2013
    6.8
    Medium

    CVE-2013-2847

    Last Modified: 11 Apr 2025

    Race condition in the workers implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly have unspecified other impact via unknown vectors.

    Published: 22 May 2013
    7.2
    High

    CVE-2013-3496

    Last Modified: 11 Apr 2025

    Infotecs ViPNet Client 3.2.10 (15632) and earlier, ViPNet Coordinator 3.2.10 (15632) and earlier, ViPNet Personal Firewall 3.1 and earlier, and ViPNet SafeDisk 4.1 (0.5643) and earlier use weak permissions (Everyone: Full Control) for a folder under %PROGRAMFILES%\Infotecs, which allows local users to gain privileges via a Trojan horse (1) executable file or (2) DLL file.

    Published: 22 May 2013
    2.1
    Low

    CVE-2013-0941

    Last Modified: 11 Apr 2025

    EMC RSA Authentication API before 8.1 SP1, RSA Web Agent before 5.3.5 for Apache Web Server, RSA Web Agent before 5.3.5 for IIS, RSA PAM Agent before 7.0, and RSA Agent before 6.1.4 for Microsoft Windows use an improper encryption algorithm and a weak key for maintaining the stored data of the node secret for the SecurID Authentication API, which allows local users to obtain sensitive information via cryptographic attacks on this data.

    Published: 22 May 2013
    4.3
    Medium

    CVE-2013-0942

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in EMC RSA Authentication Agent 7.1 before 7.1.1 for Web for Internet Information Services, and 7.1 before 7.1.1 for Web for Apache, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 May 2013
    4.3
    Medium

    CVE-2013-2849

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Google Chrome before 27.0.1453.93 allow user-assisted remote attackers to inject arbitrary web script or HTML via vectors involving a (1) drag-and-drop or (2) copy-and-paste operation.

    Published: 22 May 2013
    5
    Medium

    CVE-2013-4635

    Last Modified: 11 Apr 2025

    Integer overflow in the SdnToJewish function in jewish.c in the Calendar component in PHP before 5.3.26 and 5.4.x before 5.4.16 allows context-dependent attackers to cause a denial of service (application hang) via a large argument to the jdtojewish function.

    Published: 22 May 2013
    4.3
    Medium

    CVE-2013-1885

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) tus/ or (2) tus/tus/.

    Published: 22 May 2013
    7.5
    High

    CVE-2013-1886

    Last Modified: 11 Apr 2025

    Format string vulnerability in the token processing system (pki-tps) in Red Hat Certificate System (RHCS) 8.1 and possibly Dogtag Certificate System 9 and 10 allows remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in unspecified vectors, related to viewing certificates.

    Published: 22 May 2013
    9.3
    Critical

    CVE-2013-1965

    Last Modified: 11 Apr 2025

    Apache Struts Showcase App 2.0.0 through 2.3.13, as used in Struts 2 before 2.3.14.3, allows remote attackers to execute arbitrary OGNL code via a crafted parameter name that is not properly handled when invoking a redirect.

    Published: 22 May 2013
    8.1
    High

    CVE-2013-2115

    Last Modified: 11 Apr 2025

    Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.

    Published: 22 May 2013
    9.3
    Critical

    CVE-2013-1966

    Last Modified: 11 Apr 2025

    Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag.

    Published: 22 May 2013
    5.8
    Medium

    CVE-2007-6746

    Last Modified: 11 Apr 2025

    telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 21 May 2013
    5
    Medium

    CVE-2013-2056

    Last Modified: 11 Apr 2025

    The Inter-Satellite Sync (ISS) operation in Red Hat Network (RHN) Satellite 5.3, 5.4, and 5.5 does not properly check client "authenticity," which allows remote attackers to obtain channel content by skipping the initial authentication call.

    Published: 21 May 2013
    5
    Medium

    CVE-2013-2111

    Last Modified: 12 Apr 2025

    The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid APPEND parameters.

    Published: 20 May 2013
    3.7
    Low

    CVE-2012-4572

    Last Modified: 11 Apr 2025

    Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application.

    Published: 20 May 2013
    6.8
    Medium

    CVE-2013-0992

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-0999

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-1007

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    5
    Medium

    CVE-2013-0145

    Last Modified: 11 Apr 2025

    Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in a read request.

    Published: 19 May 2013
    6.8
    Medium

    CVE-2013-0994

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    6.8
    Medium

    CVE-2013-0995

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    6.8
    Medium

    CVE-2013-0997

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    6.8
    Medium

    CVE-2013-0998

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-1001

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-1002

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-1004

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-1005

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-1006

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-1008

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-1010

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    6.8
    Medium

    CVE-2013-1011

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    4.3
    Medium

    CVE-2013-1014

    Last Modified: 11 Apr 2025

    Apple iTunes before 11.0.3 does not properly verify X.509 certificates, which allows man-in-the-middle attackers to spoof HTTPS servers via an arbitrary valid certificate.

    Published: 19 May 2013
    6.8
    Medium

    CVE-2013-3270

    Last Modified: 11 Apr 2025

    EMC VNX Control Station before 7.1.70.2 and Celerra Control Station before 6.0.70.1 have an incorrect group ownership for unspecified script files, which allows local users to gain privileges by leveraging nasadmin group membership.

    Published: 19 May 2013