CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2013-0991

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    6.8
    Medium

    CVE-2013-0993

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    6.8
    Medium

    CVE-2013-0996

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-1000

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    9.3
    Critical

    CVE-2013-1003

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iTunes before 11.0.3, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-05-16-1.

    Published: 19 May 2013
    5
    Medium

    CVE-2014-0467

    Last Modified: 12 Apr 2025

    Buffer overflow in copy.c in Mutt before 1.5.23 allows remote attackers to cause a denial of service (crash) via a crafted RFC2047 header line, related to address expansion.

    Published: 18 May 2013
    5
    Medium

    CVE-2013-3556

    Last Modified: 11 Apr 2025

    The fragment_add_seq_common function in epan/reassemble.c in the ASN.1 BER dissector in Wireshark before r48943 has an incorrect pointer dereference during a comparison, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 17 May 2013
    5
    Medium

    CVE-2013-3558

    Last Modified: 11 Apr 2025

    The dissect_ccp_bsdcomp_opt function in epan/dissectors/packet-ppp.c in the PPP CCP dissector in Wireshark 1.8.x before 1.8.7 does not terminate a bit-field list, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 17 May 2013
    7.4
    High

    CVE-2013-2072

    Last Modified: 11 Apr 2025

    Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) and possibly gain privileges via a crafted cpumap.

    Published: 17 May 2013
    5
    Medium

    CVE-2013-3557

    Last Modified: 11 Apr 2025

    The dissect_ber_choice function in epan/dissectors/packet-ber.c in the ASN.1 BER dissector in Wireshark 1.6.x before 1.6.15 and 1.8.x before 1.8.7 does not properly initialize a certain variable, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 17 May 2013
    5
    Medium

    CVE-2013-3560

    Last Modified: 11 Apr 2025

    The dissect_dsmcc_un_download function in epan/dissectors/packet-mpeg-dsmcc.c in the MPEG DSM-CC dissector in Wireshark 1.8.x before 1.8.7 uses an incorrect format string, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 17 May 2013
    7.8
    High

    CVE-2013-3561

    Last Modified: 11 Apr 2025

    Multiple integer overflows in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (loop or application crash) via a malformed packet, related to a crash of the Websocket dissector, an infinite loop in the MySQL dissector, and a large loop in the ETCH dissector.

    Published: 17 May 2013
    5
    Medium

    CVE-2013-3562

    Last Modified: 11 Apr 2025

    Multiple integer signedness errors in the tvb_unmasked function in epan/dissectors/packet-websocket.c in the Websocket dissector in Wireshark 1.8.x before 1.8.7 allow remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 17 May 2013
    5
    Medium

    CVE-2013-3555

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-gtpv2.c in the GTPv2 dissector in Wireshark 1.8.x before 1.8.7 calls incorrect functions in certain contexts related to ciphers, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 17 May 2013
    5
    Medium

    CVE-2013-3559

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-dcp-etsi.c in the DCP ETSI dissector in Wireshark 1.8.x before 1.8.7 uses incorrect integer data types, which allows remote attackers to cause a denial of service (integer overflow, and heap memory corruption or NULL pointer dereference, and application crash) via a malformed packet.

    Published: 17 May 2013
    6.9
    Medium

    CVE-2013-1672

    Last Modified: 11 Apr 2025

    The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.

    Published: 16 May 2013
    10
    Critical

    CVE-2013-1389

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Adobe ColdFusion 9.0 before Update 11, 9.0.1 before Update 10, 9.0.2 before Update 5, and 10 before Update 10 allows remote attackers to execute arbitrary code via unknown vectors.

    Published: 16 May 2013
    10
    Critical

    CVE-2013-3342

    Last Modified: 11 Apr 2025

    Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 do not properly handle operating-system domain blacklists, which has unspecified impact and attack vectors.

    Published: 16 May 2013
    6.9
    Medium

    CVE-2013-1673

    Last Modified: 11 Apr 2025

    The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."

    Published: 16 May 2013
    Unknown

    CVE-2013-1175

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This issue was announced by the vendor and later withdrawn because it was not a vulnerability. Notes: none

    Published: 16 May 2013
    5
    Medium

    CVE-2013-1188

    Last Modified: 11 Apr 2025

    Cisco Unified Communications Manager (CUCM) does not properly limit the rate of authentication attempts, which allows remote attackers to cause a denial of service (application slowdown) via a series of requests, aka Bug ID CSCud39515.

    Published: 16 May 2013
    6.8
    Medium

    CVE-2013-1200

    Last Modified: 11 Apr 2025

    Session fixation vulnerability in Cisco Secure Access Control System (ACS) allows remote attackers to hijack web sessions via unspecified vectors, aka Bug ID CSCud95787.

    Published: 16 May 2013
    3.5
    Low

    CVE-2013-1244

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the portal module in Cisco WebEx Social allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL in the link field in a post, aka Bug ID CSCue67199.

    Published: 16 May 2013
    7.8
    High

    CVE-2013-1236

    Last Modified: 11 Apr 2025

    Cisco TelePresence Supervisor MSE 8050 before 2.3(1.31) allows remote attackers to cause a denial of service (CPU consumption or device reload) by establishing TCP connections at a high rate, aka Bug IDs CSCuf76076 and CSCuf79763.

    Published: 16 May 2013
    4
    Medium

    CVE-2013-1245

    Last Modified: 11 Apr 2025

    The user-management page in Cisco WebEx Social relies on client-side validation of values in the Screen Name, First Name, Middle Name, Last Name, Email Address, and Job Title fields, which allows remote authenticated users to bypass intended access restrictions via crafted requests, aka Bug ID CSCue67190.

    Published: 16 May 2013
    5
    Medium

    CVE-2013-1962

    Last Modified: 11 Apr 2025

    The remoteDispatchStoragePoolListAllVolumes function in the storage pool manager in libvirt 1.0.5 allows remote attackers to cause a denial of service (file descriptor consumption) via a large number of requests "to list all volumes for the particular pool."

    Published: 16 May 2013
    2.1
    Low

    CVE-2013-2096

    Last Modified: 11 Apr 2025

    OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.

    Published: 16 May 2013
    9.3
    Critical

    CVE-2013-1346

    Last Modified: 11 Apr 2025

    mpengine.dll in Microsoft Malware Protection Engine before 1.1.9506.0 on x64 platforms allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted file.

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1306

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1313.

    Published: 15 May 2013
    10
    Critical

    CVE-2013-1322

    Last Modified: 11 Apr 2025

    Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."

    Published: 15 May 2013
    7.5
    High

    CVE-2013-1337

    Last Modified: 11 Apr 2025

    Microsoft .NET Framework 4.5 does not properly create policy requirements for custom Windows Communication Foundation (WCF) endpoint authentication in certain situations involving passwords over HTTPS, which allows remote attackers to bypass authentication by sending queries to an endpoint, aka "Authentication Bypass Vulnerability."

    Published: 15 May 2013
    6.8
    Medium

    CVE-2013-0096

    Last Modified: 11 Apr 2025

    Writer in Microsoft Windows Essentials 2011 and 2012 allows remote attackers to bypass proxy settings and overwrite arbitrary files via crafted URL parameters, aka "Windows Essentials Improper URI Handling Vulnerability."

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-0811

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1307.

    Published: 15 May 2013
    4.3
    Medium

    CVE-2013-1301

    Last Modified: 11 Apr 2025

    Microsoft Visio 2003 SP3 2007 SP3, and 2010 SP1 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, aka "XML External Entities Resolution Vulnerability."

    Published: 15 May 2013
    7.8
    High

    CVE-2013-1305

    Last Modified: 11 Apr 2025

    HTTP.sys in Microsoft Windows 8, Windows Server 2012, and Windows RT allows remote attackers to cause a denial of service (infinite loop) via a crafted HTTP header, aka "HTTP.sys Denial of Service Vulnerability."

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1308

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1309 and CVE-2013-2551.

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1309

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-2551.

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1310

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 6 and 7 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1311

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1312

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer Use After Free Vulnerability."

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1317

    Last Modified: 11 Apr 2025

    Integer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper allocation-size calculation, aka "Publisher Integer Overflow Vulnerability."

    Published: 15 May 2013
    10
    Critical

    CVE-2013-1318

    Last Modified: 11 Apr 2025

    Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers access to an invalid pointer, aka "Publisher Corrupt Interface Pointer Vulnerability."

    Published: 15 May 2013
    10
    Critical

    CVE-2013-1320

    Last Modified: 11 Apr 2025

    Buffer overflow in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Buffer Overflow Vulnerability."

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1327

    Last Modified: 11 Apr 2025

    Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers an improper memory allocation, aka "Publisher Signed Integer Vulnerability."

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1328

    Last Modified: 11 Apr 2025

    Microsoft Publisher 2003 SP3, 2007 SP3, and 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers incorrect pointer handling, aka "Publisher Pointer Handling Vulnerability."

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1329

    Last Modified: 11 Apr 2025

    Integer signedness error in Microsoft Publisher 2003 SP3 allows remote attackers to execute arbitrary code via a crafted Publisher file that triggers a buffer underflow, aka "Publisher Buffer Underflow Vulnerability."

    Published: 15 May 2013
    7.2
    High

    CVE-2013-1332

    Last Modified: 11 Apr 2025

    dxgkrnl.sys (aka the DirectX graphics kernel subsystem) in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "DirectX Graphics Kernel Subsystem Double Fetch Vulnerability."

    Published: 15 May 2013
    7.2
    High

    CVE-2013-1333

    Last Modified: 11 Apr 2025

    Buffer overflow in win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 allows local users to gain privileges via a crafted application that leverages improper handling of objects in memory, aka "Win32k Buffer Overflow Vulnerability."

    Published: 15 May 2013
    7.2
    High

    CVE-2013-1334

    Last Modified: 11 Apr 2025

    win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not properly handle objects in memory, which allows local users to gain privileges via a crafted application, aka "Win32k Window Handle Vulnerability."

    Published: 15 May 2013
    9.3
    Critical

    CVE-2013-1335

    Last Modified: 11 Apr 2025

    Microsoft Word 2003 SP3 and Word Viewer allow remote attackers to execute arbitrary code via crafted shape data in a Word document, aka "Word Shape Corruption Vulnerability."

    Published: 15 May 2013