CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2013-0205

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.

    Published: 19 Mar 2013
    4.4
    Medium

    CVE-2013-0224

    Last Modified: 11 Apr 2025

    The Video module 7.x-2.x before 7.x-2.9 for Drupal, when using the FFmpeg transcoder, allows local users to execute arbitrary PHP code by modifying a temporary PHP file.

    Published: 19 Mar 2013
    2.1
    Low

    CVE-2013-0225

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.

    Published: 19 Mar 2013
    6
    Medium

    CVE-2013-0226

    Last Modified: 11 Apr 2025

    The Keyboard Shortcut Utility module 7.x-1.x before 7.x-1.1 for Drupal does not properly check node restrictions, which allows (1) remote authenticated users with the "view shortcuts" permission to read nodes or (2) remote authenticated users with the "admin shortcuts" permission to read, edit, or delete nodes via unspecified vectors.

    Published: 19 Mar 2013
    2.1
    Low

    CVE-2013-0227

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Search API Sorts module 7.x-1.x before 7.x-1.4 for Drupal allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified field labels.

    Published: 19 Mar 2013
    10
    Critical

    CVE-2013-0251

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the llogin version.

    Published: 19 Mar 2013
    5
    Medium

    CVE-2013-2263

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Citrix Access Gateway Standard Edition 5.0.x before 5.0.4.223524 allows remote attackers to access network resources via unknown attack vectors.

    Published: 19 Mar 2013
    4.9
    Medium

    CVE-2014-3122

    Last Modified: 12 Apr 2025

    The try_to_unmap_cluster function in mm/rmap.c in the Linux kernel before 3.14.3 does not properly consider which pages must be locked, which allows local users to cause a denial of service (system crash) by triggering a memory-usage pattern that requires removal of page-table mappings.

    Published: 19 Mar 2013
    9.3
    Critical

    CVE-2012-6535

    Last Modified: 11 Apr 2025

    DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted DjVu (aka .djv) file.

    Published: 19 Mar 2013
    4.9
    Medium

    CVE-2013-0287

    Last Modified: 11 Apr 2025

    The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

    Published: 19 Mar 2013
    7.5
    High

    CVE-2013-1492

    Last Modified: 11 Apr 2025

    Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.30, has unspecified impact and attack vectors, a different vulnerability than CVE-2012-0553.

    Published: 19 Mar 2013
    6
    Medium

    CVE-2013-1863

    Last Modified: 11 Apr 2025

    Samba 4.x before 4.0.4, when configured as an Active Directory domain controller, uses world-writable permissions on non-default CIFS shares, which allows remote authenticated users to read, modify, create, or delete arbitrary files via standard filesystem operations.

    Published: 19 Mar 2013
    7.5
    High

    CVE-2012-0553

    Last Modified: 11 Apr 2025

    Buffer overflow in yaSSL, as used in MySQL 5.1.x before 5.1.68 and 5.5.x before 5.5.28, has unspecified impact and attack vectors, a different vulnerability than CVE-2013-1492.

    Published: 19 Mar 2013
    6.9
    Medium

    CVE-2013-1495

    Last Modified: 11 Apr 2025

    asr in Oracle Auto Service Request in Oracle Support Tools before 4.3.2 allows local users to modify arbitrary files via a symlink attack on a predictable filename in /tmp.

    Published: 18 Mar 2013
    10
    Critical

    CVE-2013-0915

    Last Modified: 11 Apr 2025

    The GPU process in Google Chrome OS before 25.0.1364.173 allows attackers to cause a denial of service or possibly have unspecified other impact via vectors related to an "overflow."

    Published: 18 Mar 2013
    6.2
    Medium

    CVE-2013-1848

    Last Modified: 11 Apr 2025

    fs/ext3/super.c in the Linux kernel before 3.8.4 uses incorrect arguments to functions in certain circumstances related to printk input, which allows local users to conduct format-string attacks and possibly gain privileges via a crafted application.

    Published: 18 Mar 2013
    4.3
    Medium

    CVE-2013-1855

    Last Modified: 11 Apr 2025

    The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.

    Published: 18 Mar 2013
    4.3
    Medium

    CVE-2013-1857

    Last Modified: 11 Apr 2025

    The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a : sequence.

    Published: 18 Mar 2013
    5
    Medium

    CVE-2013-1854

    Last Modified: 11 Apr 2025

    The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.

    Published: 18 Mar 2013
    6.4
    Medium

    CVE-2013-2373

    Last Modified: 11 Apr 2025

    The Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 does not properly implement access control, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.

    Published: 15 Mar 2013
    5
    Medium

    CVE-2013-2371

    Last Modified: 11 Apr 2025

    The Web API in the Statistics Server in TIBCO Spotfire Statistics Services 3.3.x before 3.3.1, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to obtain sensitive information via an unspecified HTTP request.

    Published: 15 Mar 2013
    4.3
    Medium

    CVE-2013-2372

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 15 Mar 2013
    6.8
    Medium

    CVE-2013-2492

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.

    Published: 15 Mar 2013
    4.3
    Medium

    CVE-2013-0967

    Last Modified: 11 Apr 2025

    CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site.

    Published: 15 Mar 2013
    6.8
    Medium

    CVE-2013-0976

    Last Modified: 11 Apr 2025

    IOAcceleratorFamily in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted graphics image.

    Published: 15 Mar 2013
    6.8
    Medium

    CVE-2013-0960

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2013-0961.

    Published: 15 Mar 2013
    6.8
    Medium

    CVE-2013-0961

    Last Modified: 11 Apr 2025

    WebKit in Apple Safari before 6.0.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2013-0960.

    Published: 15 Mar 2013
    6.4
    Medium

    CVE-2013-0966

    Last Modified: 11 Apr 2025

    The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted pathname in a URI.

    Published: 15 Mar 2013
    4.9
    Medium

    CVE-2013-0969

    Last Modified: 11 Apr 2025

    Login Window in Apple Mac OS X before 10.8.3 does not prevent application launching with the VoiceOver feature, which allows physically proximate attackers to bypass authentication and make arbitrary System Preferences changes via unspecified use of the keyboard.

    Published: 15 Mar 2013
    4.3
    Medium

    CVE-2013-0970

    Last Modified: 11 Apr 2025

    Messages in Apple Mac OS X before 10.8.3 allows remote attackers to bypass the FaceTime call-confirmation prompt via a crafted FaceTime: URL.

    Published: 15 Mar 2013
    6.8
    Medium

    CVE-2013-0971

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in PDFKit in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted ink annotations in a PDF document.

    Published: 15 Mar 2013
    6.8
    Medium

    CVE-2013-0973

    Last Modified: 11 Apr 2025

    Software Update in Apple Mac OS X through 10.7.5 does not prevent plugin loading within the marketing-text WebView, which allows man-in-the-middle attackers to execute plugin code by modifying the client-server data stream.

    Published: 15 Mar 2013
    7.8
    High

    CVE-2013-2560

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the web interface on Foscam devices with firmware before 11.37.2.49 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated by discovering (1) web credentials or (2) Wi-Fi credentials.

    Published: 15 Mar 2013
    5.9
    Medium

    CVE-2013-2566

    Last Modified: 22 May 2026

    The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that use the same plaintext.

    Published: 14 Mar 2013
    Unknown

    CVE-2013-1825

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-2546, CVE-2013-2547, CVE-2013-2548. Reason: This candidate is a duplicate of CVE-2013-2546, CVE-2013-2547, and CVE-2013-2548. Notes: All CVE users should reference one or more of CVE-2013-2546, CVE-2013-2547, and CVE-2013-2548 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Mar 2013
    Unknown

    CVE-2012-6138

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-6536, CVE-2012-6537, CVE-2012-6538, CVE-2012-6539, CVE-2012-6540, CVE-2012-6541, CVE-2012-6542, CVE-2012-6543, CVE-2012-6544, CVE-2012-6545, CVE-2012-6546, CVE-2012-6547, CVE-2012-6548, CVE-2012-6549. Reason: This candidate is a duplicate of CVE-2012-6536, CVE-2012-6537, CVE-2012-6538, CVE-2012-6539, CVE-2012-6540, CVE-2012-6541, CVE-2012-6542, CVE-2012-6543, CVE-2012-6544, CVE-2012-6545, CVE-2012-6546, CVE-2012-6547, CVE-2012-6548, and CVE-2012-6549. Notes: All CVE users should reference one or more of CVE-2012-6536, CVE-2012-6537, CVE-2012-6538, CVE-2012-6539, CVE-2012-6540, CVE-2012-6541, CVE-2012-6542, CVE-2012-6543, CVE-2012-6544, CVE-2012-6545, CVE-2012-6546, CVE-2012-6547, CVE-2012-6548, and CVE-2012-6549 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Mar 2013
    4
    Medium

    CVE-2013-1814

    Last Modified: 11 Apr 2025

    The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.

    Published: 14 Mar 2013
    4
    Medium

    CVE-2013-1838

    Last Modified: 11 Apr 2025

    OpenStack Compute (Nova) Grizzly, Folsom (2012.2), and Essex (2012.1) does not properly implement a quota for fixed IPs, which allows remote authenticated users to cause a denial of service (resource exhaustion and failure to spawn new instances) via a large number of calls to the addFixedIp function.

    Published: 14 Mar 2013
    3.5
    Low

    CVE-2013-1840

    Last Modified: 11 Apr 2025

    The v1 API in OpenStack Glance Essex (2012.1), Folsom (2012.2), and Grizzly, when using the single-tenant Swift or S3 store, reports the location field, which allows remote authenticated users to obtain the operator's backend credentials via a request for a cached image.

    Published: 14 Mar 2013
    4
    Medium

    CVE-2013-1469

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in install.php in Piwigo before 2.4.7 allows remote attackers to read and delete arbitrary files via a .. (dot dot) in the dl parameter.

    Published: 13 Mar 2013
    7.8
    High

    CVE-2013-0074

    Last Modified: 22 Apr 2026

    Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."

    Published: 13 Mar 2013
    9.3
    Critical

    CVE-2013-1288

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 8 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CTreeNode Use After Free Vulnerability."

    Published: 13 Mar 2013
    7.8
    High

    CVE-2013-0085

    Last Modified: 11 Apr 2025

    Buffer overflow in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to cause a denial of service (W3WP process crash and site outage) via a crafted URL, aka "Buffer Overflow Vulnerability."

    Published: 13 Mar 2013
    9.3
    Critical

    CVE-2013-0089

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CMarkupBehaviorContext Use After Free Vulnerability."

    Published: 13 Mar 2013
    9.3
    Critical

    CVE-2013-0092

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer GetMarkupPtr Use After Free Vulnerability."

    Published: 13 Mar 2013
    5.4
    Medium

    CVE-2013-2206

    Last Modified: 11 Apr 2025

    The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.

    Published: 13 Mar 2013
    9.3
    Critical

    CVE-2013-0079

    Last Modified: 11 Apr 2025

    Microsoft Visio Viewer 2010 SP1 allows remote attackers to execute arbitrary code via a crafted Visio file that triggers incorrect memory allocation, aka "Visio Viewer Tree Object Type Confusion Vulnerability."

    Published: 13 Mar 2013
    7.5
    High

    CVE-2013-0080

    Last Modified: 11 Apr 2025

    Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allow remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "Callback Function Vulnerability."

    Published: 13 Mar 2013
    4.3
    Medium

    CVE-2013-0083

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Microsoft SharePoint Server 2010 SP1 allows remote attackers to inject arbitrary web script or HTML via crafted content, leading to administrative command execution, aka "SharePoint XSS Vulnerability."

    Published: 13 Mar 2013
    7.5
    High

    CVE-2013-0084

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Microsoft SharePoint Server 2010 SP1 and SharePoint Foundation 2010 SP1 allows remote attackers to bypass intended read restrictions for content, and hijack user accounts, via a crafted URL, aka "SharePoint Directory Traversal Vulnerability."

    Published: 13 Mar 2013