CVE Feed

    Dashboard / CVE

    4
    Medium

    CVE-2013-0679

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the web server in Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, allows remote authenticated users to read arbitrary files via vectors involving a query for a pathname.

    Published: 21 Mar 2013
    4
    Medium

    CVE-2013-0676

    Last Modified: 11 Apr 2025

    Siemens WinCC before 7.2, as used in SIMATIC PCS7 before 8.0 SP1 and other products, does not properly assign privileges for the database containing WebNavigator credentials, which allows remote authenticated users to obtain sensitive information via a SQL query.

    Published: 21 Mar 2013
    6.2
    Medium

    CVE-2013-0665

    Last Modified: 11 Apr 2025

    Schweitzer Engineering Laboratories (SEL) AcSELerator QuickSet before 5.12.0.1 uses weak permissions for its Program Files directory, which allows local users to replace executable files, and consequently gain privileges, via standard filesystem operations.

    Published: 21 Mar 2013
    4.3
    Medium

    CVE-2013-0668

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the HMI web application in Siemens WinCC (TIA Portal) 11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 21 Mar 2013
    4
    Medium

    CVE-2013-0669

    Last Modified: 11 Apr 2025

    The HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to cause a denial of service (daemon crash) via a crafted HTTP request.

    Published: 21 Mar 2013
    4.3
    Medium

    CVE-2013-0670

    Last Modified: 11 Apr 2025

    CRLF injection vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.

    Published: 21 Mar 2013
    4
    Medium

    CVE-2013-0671

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to read HMI web-application source code and user-defined scripts via a crafted URL.

    Published: 21 Mar 2013
    3.5
    Low

    CVE-2013-0672

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to inject arbitrary web script or HTML via unspecified data.

    Published: 21 Mar 2013
    4.6
    Medium

    CVE-2011-4515

    Last Modified: 11 Apr 2025

    Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords in world-readable and world-writable files, which allows local users to obtain sensitive information by leveraging (1) physical access or (2) Sm@rt Server access.

    Published: 21 Mar 2013
    4.3
    Medium

    CVE-2013-0667

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

    Published: 21 Mar 2013
    4.3
    Medium

    CVE-2013-1880

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Portfolio publisher servlet in the demo web application in Apache ActiveMQ before 5.9.0 allows remote attackers to inject arbitrary web script or HTML via the refresh parameter to demo/portfolioPublish, a different vulnerability than CVE-2012-6092.

    Published: 21 Mar 2013
    4.3
    Medium

    CVE-2013-1879

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in scheduled.jsp in Apache ActiveMQ 5.8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via vectors involving the "cron of a message."

    Published: 21 Mar 2013
    7.5
    High

    CVE-2013-1875

    Last Modified: 11 Apr 2025

    command_wrap.rb in the command_wrap Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL or filename.

    Published: 20 Mar 2013
    7.5
    High

    CVE-2013-2615

    Last Modified: 11 Apr 2025

    lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

    Published: 20 Mar 2013
    7.5
    High

    CVE-2013-2616

    Last Modified: 11 Apr 2025

    lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.

    Published: 20 Mar 2013
    7.8
    High

    CVE-2013-0711

    Last Modified: 11 Apr 2025

    IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to cause a denial of service (daemon outage) via a crafted authentication request.

    Published: 20 Mar 2013
    6.8
    Medium

    CVE-2013-0712

    Last Modified: 11 Apr 2025

    IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a crafted packet.

    Published: 20 Mar 2013
    6.8
    Medium

    CVE-2013-0713

    Last Modified: 11 Apr 2025

    IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a crafted pty request.

    Published: 20 Mar 2013
    10
    Critical

    CVE-2013-0714

    Last Modified: 11 Apr 2025

    IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote attackers to execute arbitrary code or cause a denial of service (daemon hang) via a crafted public-key authentication request.

    Published: 20 Mar 2013
    4
    Medium

    CVE-2013-0715

    Last Modified: 11 Apr 2025

    The WebCLI component in Wind River VxWorks 5.5 through 6.9 allows remote authenticated users to cause a denial of service (CLI session crash) via a crafted command string.

    Published: 20 Mar 2013
    5
    Medium

    CVE-2013-0716

    Last Modified: 11 Apr 2025

    The web server in Wind River VxWorks 5.5 through 6.9 allows remote attackers to cause a denial of service (daemon crash) via a crafted URI.

    Published: 20 Mar 2013
    9.3
    Critical

    CVE-2013-1750

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in RealNetworks RealPlayer before 16.0.1.18 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers to execute arbitrary code via a malformed MP4 file.

    Published: 20 Mar 2013
    Unknown

    CVE-2013-1877

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2616. Reason: This candidate is a duplicate of CVE-2013-2616. Notes: All CVE users should reference CVE-2013-2616 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Mar 2013
    Unknown

    CVE-2013-1878

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2617. Reason: This candidate is a duplicate of CVE-2013-2617. Notes: All CVE users should reference CVE-2013-2617 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Mar 2013
    Unknown

    CVE-2013-1876

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2615. Reason: This candidate is a duplicate of CVE-2013-2615. Notes: All CVE users should reference CVE-2013-2615 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Mar 2013
    7.1
    High

    CVE-2013-1653

    Last Modified: 11 Apr 2025

    Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.

    Published: 20 Mar 2013
    7.5
    High

    CVE-2013-1655

    Last Modified: 11 Apr 2025

    Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, when running Ruby 1.9.3 or later, allows remote attackers to execute arbitrary code via vectors related to "serialized attributes."

    Published: 20 Mar 2013
    7.5
    High

    CVE-2013-0232

    Last Modified: 11 Apr 2025

    includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.

    Published: 20 Mar 2013
    5
    Medium

    CVE-2013-0332

    Last Modified: 11 Apr 2025

    Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) view, (2) request, or (3) action parameter.

    Published: 20 Mar 2013
    6.4
    Medium

    CVE-2013-1843

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in the Access tracking mechanism in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 20 Mar 2013
    7.5
    High

    CVE-2013-1842

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in the Extbase Framework in TYPO3 4.5.x before 4.5.24, 4.6.x before 4.6.17, 4.7.x before 4.7.9, and 6.0.x before 6.0.3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "the Query Object Model and relation values."

    Published: 20 Mar 2013
    7.2
    High

    CVE-2012-5938

    Last Modified: 11 Apr 2025

    The installation process in IBM InfoSphere Information Server 8.1, 8.5, 8.7, and 9.1 on UNIX and Linux sets incorrect permissions and ownerships for unspecified files, which allows local users to bypass intended access restrictions via standard filesystem operations.

    Published: 20 Mar 2013
    2.1
    Low

    CVE-2013-0978

    Last Modified: 11 Apr 2025

    The ARM prefetch abort handler in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not ensure that it has been invoked in an abort context, which makes it easier for local users to bypass the ASLR protection mechanism via crafted code.

    Published: 20 Mar 2013
    1.9
    Low

    CVE-2013-0979

    Last Modified: 11 Apr 2025

    lockdownd in Lockdown in Apple iOS before 6.1.3 does not properly consider file types during the permission-setting step of a backup restoration, which allows local users to change the permissions of arbitrary files via a backup that contains a pathname with a symlink.

    Published: 20 Mar 2013
    2.1
    Low

    CVE-2013-0980

    Last Modified: 11 Apr 2025

    The Passcode Lock implementation in Apple iOS before 6.1.3 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging an error in the emergency-call feature.

    Published: 20 Mar 2013
    7.2
    High

    CVE-2013-0981

    Last Modified: 11 Apr 2025

    The IOUSBDeviceFamily driver in the USB implementation in the kernel in Apple iOS before 6.1.3 and Apple TV before 5.2.1 accesses pipe object pointers that originated in userspace, which allows local users to gain privileges via crafted code.

    Published: 20 Mar 2013
    4.6
    Medium

    CVE-2013-0977

    Last Modified: 11 Apr 2025

    dyld in Apple iOS before 6.1.3 and Apple TV before 5.2.1 does not properly manage the state of file loading for Mach-O executable files, which allows local users to bypass intended code-signing requirements via a file that contains overlapping segments.

    Published: 20 Mar 2013
    6.8
    Medium

    CVE-2013-1865

    Last Modified: 11 Apr 2025

    OpenStack Keystone Folsom (2012.2) does not properly perform revocation checks for Keystone PKI tokens when done through a server, which allows remote attackers to bypass intended access restrictions via a revoked PKI token.

    Published: 20 Mar 2013
    6.2
    Medium

    CVE-2013-1798

    Last Modified: 11 Apr 2025

    The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG_WINDOW operations, which allows guest OS users to obtain sensitive information from host OS memory or cause a denial of service (host OS OOPS) via a crafted application.

    Published: 20 Mar 2013
    5.8
    Medium

    CVE-2012-5662

    Last Modified: 12 Apr 2025

    x3270 before 3.3.12ga12 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

    Published: 20 Mar 2013
    6.8
    Medium

    CVE-2013-1796

    Last Modified: 11 Apr 2025

    The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_KVM_SYSTEM_TIME operation, which allows guest OS users to cause a denial of service (buffer overflow and host OS memory corruption) or possibly have unspecified other impact via a crafted application.

    Published: 20 Mar 2013
    6.8
    Medium

    CVE-2013-1797

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 allows guest OS users to cause a denial of service (host OS memory corruption) or possibly have unspecified other impact via a crafted application that triggers use of a guest physical address (GPA) in (1) movable or (2) removable memory during an MSR_KVM_SYSTEM_TIME kvm_set_msr_common operation.

    Published: 20 Mar 2013
    5.8
    Medium

    CVE-2013-1856

    Last Modified: 11 Apr 2025

    The ActiveSupport::XmlMini_JDOM backend in lib/active_support/xml_mini/jdom.rb in the Active Support component in Ruby on Rails 3.0.x and 3.1.x before 3.1.12 and 3.2.x before 3.2.13, when JRuby is used, does not properly restrict the capabilities of the XML parser, which allows remote attackers to read arbitrary files or cause a denial of service (resource consumption) via vectors involving (1) an external DTD or (2) an external entity declaration in conjunction with an entity reference.

    Published: 19 Mar 2013
    6.8
    Medium

    CVE-2013-0717

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities in the web-based management utility on the NEC AtermWR9500N, AtermWR8600N, AtermWR8370N, AtermWR8160N, AtermWM3600R, and AtermWM3450RN routers allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.

    Published: 19 Mar 2013
    Unknown

    CVE-2012-4223

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2012. Notes: none

    Published: 19 Mar 2013
    Unknown

    CVE-2012-4224

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2012. Notes: none

    Published: 19 Mar 2013
    5.5
    Medium

    CVE-2013-0505

    Last Modified: 11 Apr 2025

    IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.

    Published: 19 Mar 2013
    4.3
    Medium

    CVE-2013-0506

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Sterling Order Management 8.0 before HF127, 8.5 before HF89, 9.0 before HF69, 9.1.0 before FP41, and 9.2.0 before FP13 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 19 Mar 2013
    6
    Medium

    CVE-2013-0206

    Last Modified: 11 Apr 2025

    Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.

    Published: 19 Mar 2013
    6.8
    Medium

    CVE-2013-0207

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Mark Complete module 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

    Published: 19 Mar 2013