CVE Feed

    Dashboard / CVE

    5.8
    Medium

    CVE-2012-5770

    Last Modified: 11 Apr 2025

    The SSL configuration in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.x before 7.2.1.4 supports the MD5 hash algorithm, which makes it easier for man-in-the-middle attackers to spoof servers and decrypt network traffic via a brute-force attack.

    Published: 6 Mar 2013
    3.3
    Low

    CVE-2013-2484

    Last Modified: 11 Apr 2025

    The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 6 Mar 2013
    10
    Critical

    CVE-2013-1491

    Last Modified: 11 Apr 2025

    The Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, 5.0 Update 41 and earlier, and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via vectors related to 2D, as demonstrated by Joshua Drake during a Pwn2Own competition at CanSecWest 2013.

    Published: 6 Mar 2013
    4.7
    Medium

    CVE-2013-1792

    Last Modified: 11 Apr 2025

    Race condition in the install_user_keyrings function in security/keys/process_keys.c in the Linux kernel before 3.8.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) via crafted keyctl system calls that trigger keyring operations in simultaneous threads.

    Published: 6 Mar 2013
    3.3
    Low

    CVE-2013-2475

    Last Modified: 11 Apr 2025

    The TCP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 6 Mar 2013
    6.1
    Medium

    CVE-2013-2476

    Last Modified: 11 Apr 2025

    The dissect_hartip function in epan/dissectors/packet-hartip.c in the HART/IP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a packet with a header that is too short.

    Published: 6 Mar 2013
    3.3
    Low

    CVE-2013-2479

    Last Modified: 11 Apr 2025

    The dissect_mpls_echo_tlv_dd_map function in epan/dissectors/packet-mpls-echo.c in the MPLS Echo dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via invalid Sub-tlv data.

    Published: 6 Mar 2013
    3.3
    Low

    CVE-2013-2480

    Last Modified: 11 Apr 2025

    The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 6 Mar 2013
    2.9
    Low

    CVE-2013-2481

    Last Modified: 11 Apr 2025

    Integer signedness error in the dissect_mount_dirpath_call function in epan/dissectors/packet-mount.c in the Mount dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6, when nfs_file_name_snooping is enabled, allows remote attackers to cause a denial of service (application crash) via a negative length value.

    Published: 6 Mar 2013
    6.1
    Medium

    CVE-2013-2482

    Last Modified: 11 Apr 2025

    The AMPQ dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

    Published: 6 Mar 2013
    3.3
    Low

    CVE-2013-2483

    Last Modified: 11 Apr 2025

    The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACN_DMP_ADT_D_RE DMP data.

    Published: 6 Mar 2013
    7.8
    High

    CVE-2013-2487

    Last Modified: 11 Apr 2025

    epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses incorrect integer data types, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet, related to the (1) dissect_icecandidates, (2) dissect_kinddata, (3) dissect_nodeid_list, (4) dissect_storeans, (5) dissect_storereq, (6) dissect_storeddataspecifier, (7) dissect_fetchreq, (8) dissect_findans, (9) dissect_diagnosticinfo, (10) dissect_diagnosticresponse, (11) dissect_reload_messagecontents, and (12) dissect_reload_message functions, a different vulnerability than CVE-2013-2486.

    Published: 6 Mar 2013
    5
    Medium

    CVE-2013-2488

    Last Modified: 11 Apr 2025

    The DTLS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not validate the fragment offset before invoking the reassembly state machine, which allows remote attackers to cause a denial of service (application crash) via a large offset value that triggers write access to an invalid memory location.

    Published: 6 Mar 2013
    6.3
    Medium

    CVE-2013-2561

    Last Modified: 11 Apr 2025

    OpenFabrics ibutils 1.5.7 allows local users to overwrite arbitrary files via a symlink attack on (1) ibdiagnet.db, (2) ibdiagnet.fdbs, (3) ibdiagnet_ibis.log, (4) ibdiagnet.log, (5) ibdiagnet.lst, (6) ibdiagnet.mcfdbs, (7) ibdiagnet.pkey, (8) ibdiagnet.psl, (9) ibdiagnet.slvl, or (10) ibdiagnet.sm in /tmp/.

    Published: 6 Mar 2013
    6.8
    Medium

    CVE-2012-4446

    Last Modified: 11 Apr 2025

    The default configuration for Apache Qpid 0.20 and earlier, when the federation_tag attribute is enabled, accepts AMQP connections without checking the source user ID, which allows remote attackers to bypass authentication and have other unspecified impact via an AMQP request.

    Published: 6 Mar 2013
    3.3
    Low

    CVE-2013-0248

    Last Modified: 11 Apr 2025

    The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.

    Published: 6 Mar 2013
    10
    Critical

    CVE-2013-0402

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier allows remote attackers to execute arbitrary code via unspecified vectors related to JavaFX, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013.

    Published: 6 Mar 2013
    3.3
    Low

    CVE-2013-2477

    Last Modified: 11 Apr 2025

    The CSN.1 dissector in Wireshark 1.8.x before 1.8.6 does not properly manage function pointers, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.

    Published: 6 Mar 2013
    3.3
    Low

    CVE-2013-2478

    Last Modified: 11 Apr 2025

    The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allows remote attackers to cause a denial of service (application crash) via a malformed packet that (1) triggers an integer overflow or (2) has embedded '\0' characters in a string.

    Published: 6 Mar 2013
    6.1
    Medium

    CVE-2013-2485

    Last Modified: 11 Apr 2025

    The FCSP dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

    Published: 6 Mar 2013
    6.1
    Medium

    CVE-2013-2486

    Last Modified: 11 Apr 2025

    The dissect_diagnosticrequest function in epan/dissectors/packet-reload.c in the REsource LOcation And Discovery (aka RELOAD) dissector in Wireshark 1.8.x before 1.8.6 uses an incorrect integer data type, which allows remote attackers to cause a denial of service (infinite loop) via crafted integer values in a packet.

    Published: 6 Mar 2013
    5.4
    Medium

    CVE-2013-0931

    Last Modified: 11 Apr 2025

    EMC RSA Authentication Agent 7.1.x before 7.1.2 on Windows does not enforce the Quick PIN Unlock timeout feature, which allows physically proximate attackers to bypass the passcode requirement for a screensaved session by entering a PIN after timeout expiration.

    Published: 5 Mar 2013
    4.3
    Medium

    CVE-2012-4855

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the web services framework in IBM WebSphere Commerce 6.0 through 6.0.0.11 and 7.0 through 7.0.0.6 allows remote attackers to cause a denial of service (login outage) via unknown vectors.

    Published: 5 Mar 2013
    7.8
    High

    CVE-2013-1839

    Last Modified: 11 Apr 2025

    The strHdrAcptLangGetItem function in errorpage.cc in Squid 3.2.x before 3.2.9 and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a "," character in an Accept-Language header.

    Published: 5 Mar 2013
    5
    Medium

    CVE-2012-4458

    Last Modified: 11 Apr 2025

    The AMQP type decoder in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (memory consumption and server crash) via a large number of zero width elements in the client-properties map in a connection.start-ok message.

    Published: 5 Mar 2013
    5
    Medium

    CVE-2012-4460

    Last Modified: 11 Apr 2025

    The serializing/deserializing functions in the qpid::framing::Buffer class in Apache Qpid 0.20 and earlier allow remote attackers to cause a denial of service (assertion failure and daemon exit) via unspecified vectors. NOTE: this issue could also trigger an out-of-bounds read, but it might not trigger a crash.

    Published: 5 Mar 2013
    4.3
    Medium

    CVE-2013-1849

    Last Modified: 11 Apr 2025

    The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a PROPFIND request for an activity URL.

    Published: 5 Mar 2013
    5
    Medium

    CVE-2013-1861

    Last Modified: 11 Apr 2025

    MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.

    Published: 5 Mar 2013
    5
    Medium

    CVE-2012-4459

    Last Modified: 11 Apr 2025

    Integer overflow in the qpid::framing::Buffer::checkAvailable function in Apache Qpid 0.20 and earlier allows remote attackers to cause a denial of service (crash) via a crafted message, which triggers an out-of-bounds read.

    Published: 5 Mar 2013
    5
    Medium

    CVE-2013-0909

    Last Modified: 11 Apr 2025

    The XSS Auditor in Google Chrome before 25.0.1364.152 allows remote attackers to obtain sensitive HTTP Referer information via unspecified vectors.

    Published: 4 Mar 2013
    7.5
    High

    CVE-2013-0902

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 4 Mar 2013
    7.5
    High

    CVE-2013-0903

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of browser navigation.

    Published: 4 Mar 2013
    7.5
    High

    CVE-2013-0904

    Last Modified: 11 Apr 2025

    The Web Audio implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 4 Mar 2013
    7.5
    High

    CVE-2013-0905

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving an SVG animation.

    Published: 4 Mar 2013
    7.5
    High

    CVE-2013-0906

    Last Modified: 11 Apr 2025

    The IndexedDB implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 4 Mar 2013
    7.5
    High

    CVE-2013-0907

    Last Modified: 11 Apr 2025

    Race condition in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of media threads.

    Published: 4 Mar 2013
    7.5
    High

    CVE-2013-0908

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.152 does not properly manage bindings of extension processes, which has unspecified impact and attack vectors.

    Published: 4 Mar 2013
    7.5
    High

    CVE-2013-0911

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to have an unspecified impact via vectors related to databases.

    Published: 4 Mar 2013
    7.5
    High

    CVE-2013-0910

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.152 does not properly manage the interaction between the browser process and renderer processes during authorization of the loading of a plug-in, which makes it easier for remote attackers to bypass intended access restrictions via vectors involving a blocked plug-in.

    Published: 4 Mar 2013
    10
    Critical

    CVE-2013-0809

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the 2D component in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code via unknown vectors, a different vulnerability than CVE-2013-1493.

    Published: 4 Mar 2013
    10
    Critical

    CVE-2013-1493

    Last Modified: 11 Apr 2025

    The color management (CMM) functionality in the 2D component in Oracle Java SE 7 Update 15 and earlier, 6 Update 41 and earlier, and 5.0 Update 40 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (crash) via an image with crafted raster parameters, which triggers (1) an out-of-bounds read or (2) memory corruption in the JVM, as exploited in the wild in February 2013.

    Published: 4 Mar 2013
    2.1
    Low

    CVE-2013-7421

    Last Modified: 12 Apr 2025

    The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.

    Published: 4 Mar 2013
    7.5
    High

    CVE-2013-1667

    Last Modified: 11 Apr 2025

    The rehash mechanism in Perl 5.8.2 through 5.16.x allows context-dependent attackers to cause a denial of service (memory consumption and crash) via a crafted hash key.

    Published: 4 Mar 2013
    2.1
    Low

    CVE-2014-9644

    Last Modified: 12 Apr 2025

    The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.

    Published: 4 Mar 2013
    6.1
    Medium

    CVE-2012-6026

    Last Modified: 11 Apr 2025

    The HTTP Profiler on the Cisco Aironet Access Point with software 15.2 and earlier does not properly manage buffers, which allows remote attackers to cause a denial of service (device reload) via crafted HTTP requests, aka Bug ID CSCuc62460.

    Published: 3 Mar 2013
    6.6
    Medium

    CVE-2013-1762

    Last Modified: 11 Apr 2025

    stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow.

    Published: 3 Mar 2013
    4.3
    Medium

    CVE-2012-2177

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows user-assisted remote attackers to inject arbitrary web script or HTML via vectors related to the search feature.

    Published: 2 Mar 2013
    4.3
    Medium

    CVE-2012-4835

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 2 Mar 2013
    3.5
    Low

    CVE-2012-4836

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted string that is not properly handled during rendering of stored data.

    Published: 2 Mar 2013
    4
    Medium

    CVE-2012-4837

    Last Modified: 11 Apr 2025

    IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote authenticated users to conduct XPath injection attacks, and read arbitrary XML files, via unspecified vectors.

    Published: 2 Mar 2013