CVE Feed

    Dashboard / CVE

    2.1
    Low

    CVE-2013-1956

    Last Modified: 11 Apr 2025

    The create_user_ns function in kernel/user_namespace.c in the Linux kernel before 3.8.6 does not check whether a chroot directory exists that differs from the namespace root directory, which allows local users to bypass intended filesystem restrictions via a crafted clone system call.

    Published: 24 Apr 2013
    4.7
    Medium

    CVE-2013-1957

    Last Modified: 11 Apr 2025

    The clone_mnt function in fs/namespace.c in the Linux kernel before 3.8.6 does not properly restrict changes to the MNT_READONLY flag, which allows local users to bypass an intended read-only property of a filesystem by leveraging a separate mount namespace.

    Published: 24 Apr 2013
    1.9
    Low

    CVE-2013-1958

    Last Modified: 11 Apr 2025

    The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.8.6 does not properly enforce capability requirements for controlling the PID value associated with a UNIX domain socket, which allows local users to bypass intended access restrictions by leveraging the time interval during which a user namespace has been created but a PID namespace has not been created.

    Published: 24 Apr 2013
    6.8
    Medium

    CVE-2013-0543

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 24 Apr 2013
    6.8
    Medium

    CVE-2013-1088

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in Novell iManager 2.7 before SP6 Patch 1 allows remote attackers to hijack the authentication of arbitrary users by leveraging improper request validation by iManager code deployed within an Apache Tomcat container.

    Published: 24 Apr 2013
    5
    Medium

    CVE-2013-1195

    Last Modified: 11 Apr 2025

    The time-based ACL implementation on Cisco Adaptive Security Appliances (ASA) devices, and in Cisco Firewall Services Module (FWSM), does not properly handle periodic statements for the time-range command, which allows remote attackers to bypass intended access restrictions by sending network traffic during denied time periods, aka Bug IDs CSCuf79091 and CSCug45850.

    Published: 24 Apr 2013
    1.9
    Low

    CVE-2012-6140

    Last Modified: 11 Apr 2025

    pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions and discover a shared secret via standard filesystem operations, a different vulnerability than CVE-2013-0258.

    Published: 24 Apr 2013
    1.9
    Low

    CVE-2013-0541

    Last Modified: 11 Apr 2025

    Buffer overflow in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Windows, when a localOS registry is used in conjunction with WebSphere Identity Manger (WIM), allows local users to cause a denial of service (daemon crash) via unspecified vectors.

    Published: 24 Apr 2013
    4.3
    Medium

    CVE-2013-0542

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via crafted field values.

    Published: 24 Apr 2013
    4
    Medium

    CVE-2013-0544

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the Administrative Console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux and UNIX allows remote authenticated users to modify data via unspecified vectors.

    Published: 24 Apr 2013
    4.3
    Medium

    CVE-2013-0565

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the RPC adapter for the Web 2.0 and Mobile toolkit in IBM WebSphere Application Server (WAS) 8.5 before 8.5.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted response.

    Published: 24 Apr 2013
    5
    Medium

    CVE-2013-1214

    Last Modified: 11 Apr 2025

    The scripts editor in Cisco Unified Contact Center Express (aka Unified CCX) does not properly manage privileges for anonymous logins, which allows remote attackers to read arbitrary scripts by visiting the scripts repository directory, aka Bug ID CSCuf77546.

    Published: 24 Apr 2013
    6.8
    Medium

    CVE-2013-1217

    Last Modified: 11 Apr 2025

    The generic input/output control implementation in Cisco IOS does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) by sending many SNMP requests at the same time, aka Bug ID CSCub41105.

    Published: 24 Apr 2013
    10
    Critical

    CVE-2013-3268

    Last Modified: 11 Apr 2025

    Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.

    Published: 24 Apr 2013
    7.2
    High

    CVE-2012-5218

    Last Modified: 11 Apr 2025

    HP ElitePad 900 PCs with BIOS F.0x before F.01 Update 1.0.0.8 do not enable the Secure Boot feature, which allows local users to bypass intended BIOS restrictions and boot unintended operating systems via unspecified vectors.

    Published: 24 Apr 2013
    3.5
    Low

    CVE-2013-0540

    Last Modified: 11 Apr 2025

    IBM WebSphere Application Server (WAS) Liberty Profile 8.5 before 8.5.0.2, when SSL is not enabled, does not properly validate authentication cookies, which allows remote authenticated users to bypass intended access restrictions via an HTTP session.

    Published: 24 Apr 2013
    5.8
    Medium

    CVE-2013-4347

    Last Modified: 12 Apr 2025

    The (1) make_nonce, (2) generate_nonce, and (3) generate_verifier functions in SimpleGeo python-oauth2 uses weak random numbers to generate nonces, which makes it easier for remote attackers to guess the nonce via a brute force attack.

    Published: 24 Apr 2013
    4.3
    Medium

    CVE-2013-0503

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Bookmarks component in IBM Lotus Connections before 4.0 CR3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Apr 2013
    5
    Medium

    CVE-2013-0584

    Last Modified: 11 Apr 2025

    The Data Replication Dashboard component in IBM InfoSphere Replication Server 9.7 and 10.x before 10.2.0.0-b113 allows remote attackers to obtain a list of all user accounts, along with information about whether each account requires a password, via unspecified vectors.

    Published: 23 Apr 2013
    4.3
    Medium

    CVE-2012-5949

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject content, and conduct phishing attacks, via vectors involving (1) the html/en/default/ directory, (2) birt/frameset, (3) WebProcess.srv, (4) sqa/html/en/default/reportTemplate/reportTemplateOrderCols.jsp, or (5) a/html/en/default/om2/omObjectFinder.jsp.

    Published: 23 Apr 2013
    4.3
    Medium

    CVE-2012-5948

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) WebProcess.srv, (2) the html/en/default/ directory, (3) Widget/resource, (4) birt/frameset, or (5) ganttlib/gantt-jws.jnlp.

    Published: 23 Apr 2013
    6.8
    Medium

    CVE-2012-5950

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in IBM TRIRIGA Application Platform 2.x and 3.x before 3.3, and 8, allow remote attackers to hijack the authentication of arbitrary users for requests that modify data records via vectors involving (1) the html/en/default/ directory or (2) sqa/html/en/default/process/comm/saveProps.jsp.

    Published: 23 Apr 2013
    6.9
    Medium

    CVE-2013-1979

    Last Modified: 11 Apr 2025

    The scm_set_cred function in include/net/scm.h in the Linux kernel before 3.8.11 uses incorrect uid and gid values during credentials passing, which allows local users to gain privileges via a crafted application.

    Published: 23 Apr 2013
    9.3
    Critical

    CVE-2013-0138

    Last Modified: 11 Apr 2025

    BitZipper 2013 before Update 1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted ZIP archive.

    Published: 22 Apr 2013
    1.9
    Low

    CVE-2013-0122

    Last Modified: 11 Apr 2025

    The avast! Mobile Security application before 2.0.4400 for Android allows attackers to cause a denial of service (application crash) via a crafted application that sends an intent to com.avast.android.mobilesecurity.app.scanner.DeleteFileActivity with zero arguments.

    Published: 22 Apr 2013
    7.8
    High

    CVE-2013-0700

    Last Modified: 11 Apr 2025

    Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to TCP port 102 (aka the ISO-TSAP port).

    Published: 22 Apr 2013
    7.8
    High

    CVE-2013-2780

    Last Modified: 11 Apr 2025

    Siemens SIMATIC S7-1200 PLCs 2.x and 3.x allow remote attackers to cause a denial of service (defect-mode transition and control outage) via crafted packets to UDP port 161 (aka the SNMP port).

    Published: 22 Apr 2013
    6.8
    Medium

    CVE-2013-2697

    Last Modified: 14 Jan 2026

    Cross-site request forgery (CSRF) vulnerability in the WP-DownloadManager plugin before 1.61 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

    Published: 19 Apr 2013
    3.5
    Low

    CVE-2013-0129

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in pd-admin before 4.17 allow remote authenticated users to inject arbitrary web script or HTML via (1) the WebFTP Overview "Create new directory" field or (2) the body of an e-mail autoresponder message.

    Published: 19 Apr 2013
    4.3
    Medium

    CVE-2013-1086

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise before 8.0.3 HP3, and 2012 before SP2, allows remote attackers to inject arbitrary web script or HTML via vectors involving an onError attribute.

    Published: 19 Apr 2013
    10
    Critical

    CVE-2013-3075

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities 7.10 and CitectScada 7.10r1, allow remote attackers to execute arbitrary code via a long string, as demonstrated by a long WzTitle property value to a certain ActiveX control.

    Published: 19 Apr 2013
    5
    Medium

    CVE-2013-3210

    Last Modified: 11 Apr 2025

    Opera before 12.15 does not properly block top-level domains in Set-Cookie headers, which allows remote attackers to obtain sensitive information by leveraging control of a different web site in the same top-level domain.

    Published: 19 Apr 2013
    10
    Critical

    CVE-2013-3211

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Opera before 12.15 has unknown impact and attack vectors, related to a "moderately severe issue."

    Published: 19 Apr 2013
    4.8
    Medium

    CVE-2013-7239

    Last Modified: 11 Apr 2025

    memcached before 1.4.17 allows remote attackers to bypass authentication by sending an invalid request with SASL credentials, then sending another request with incorrect SASL credentials.

    Published: 19 Apr 2013
    2.1
    Low

    CVE-2013-2006

    Last Modified: 11 Apr 2025

    OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by reading the log file.

    Published: 19 Apr 2013
    5.1
    Medium

    CVE-2013-1862

    Last Modified: 11 Apr 2025

    mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.

    Published: 19 Apr 2013
    4.9
    Medium

    CVE-2013-1199

    Last Modified: 11 Apr 2025

    Race condition in the CIFS implementation in the rewriter module in the Clientless SSL VPN component on Cisco Adaptive Security Appliances (ASA) devices allows remote authenticated users to cause a denial of service (device reload) by accessing resources within multiple sessions, aka Bug ID CSCub58996.

    Published: 18 Apr 2013
    6.8
    Medium

    CVE-2013-0132

    Last Modified: 11 Apr 2025

    The suexec implementation in Parallels Plesk Panel 11.0.9 contains a cgi-wrapper whitelist entry, which allows user-assisted remote attackers to execute arbitrary PHP code via a request containing crafted environment variables.

    Published: 18 Apr 2013
    7.2
    High

    CVE-2013-0133

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in /usr/local/psa/admin/sbin/wrapper in Parallels Plesk Panel 11.0.9 allows local users to gain privileges via a crafted PATH environment variable.

    Published: 18 Apr 2013
    7.8
    High

    CVE-2013-0139

    Last Modified: 11 Apr 2025

    The Arecont Vision AV1355DN MegaDome camera allows remote attackers to cause a denial of service (video-capture outage) via a packet to UDP port 69.

    Published: 18 Apr 2013
    5
    Medium

    CVE-2013-1194

    Last Modified: 11 Apr 2025

    The ISAKMP implementation on Cisco Adaptive Security Appliances (ASA) devices generates different responses for IKE aggressive-mode messages depending on whether invalid VPN groups are specified, which allows remote attackers to enumerate groups via a series of messages, aka Bug ID CSCue73708.

    Published: 18 Apr 2013
    7.1
    High

    CVE-2013-1176

    Last Modified: 11 Apr 2025

    The DSP card on Cisco TelePresence MCU 4500 and 4501 devices before 4.3(2.30), TelePresence MCU MSE 8510 devices before 4.3(2.30), and TelePresence Server before 2.3(1.55) does not properly validate H.264 data, which allows remote attackers to cause a denial of service (device reload) via crafted RTP packets in a (1) SIP session or (2) H.323 session, aka Bug IDs CSCuc11328 and CSCub05448.

    Published: 18 Apr 2013
    7.5
    High

    CVE-2013-1177

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in Cisco Network Admission Control (NAC) Manager before 4.8.3.1 and 4.9.x before 4.9.2 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka Bug ID CSCub23095.

    Published: 18 Apr 2013
    7.5
    High

    CVE-2013-1748

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) edit.php or (2) import.php. NOTE: the view.php id vector is already covered by CVE-2008-2565.1 and the edit.php id vector is already covered by CVE-2008-2565.2.

    Published: 18 Apr 2013
    4.3
    Medium

    CVE-2013-1749

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in edit.php in PHP Address Book 8.2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via the Address field.

    Published: 18 Apr 2013
    10
    Critical

    CVE-2012-4715

    Last Modified: 11 Apr 2025

    Buffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a UDP packet with a certain integer length value that is (1) too large or (2) too small, leading to improper handling by Logger.dll.

    Published: 18 Apr 2013
    6.6
    Medium

    CVE-2013-0687

    Last Modified: 11 Apr 2025

    The installer routine in Schneider Electric MiCOM S1 Studio uses world-writable permissions for executable files, which allows local users to modify the service or the configuration files, and consequently gain privileges or trigger incorrect protective-relay operation, via a Trojan horse executable file.

    Published: 18 Apr 2013
    7.1
    High

    CVE-2012-4695

    Last Modified: 11 Apr 2025

    LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage) via a zero-byte UDP packet that is not properly handled by Logger.dll.

    Published: 18 Apr 2013
    7.8
    High

    CVE-2012-4714

    Last Modified: 11 Apr 2025

    Integer overflow in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that specifies a large integer value.

    Published: 18 Apr 2013
    7.8
    High

    CVE-2012-4713

    Last Modified: 11 Apr 2025

    Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that specifies a negative integer value.

    Published: 18 Apr 2013