CVE Feed

    Dashboard / CVE

    9.3
    Critical

    CVE-2012-0439

    Last Modified: 11 Apr 2025

    An ActiveX control in gwcls1.dll in the client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code via (1) a pointer argument to the SetEngine method or (2) an XPItem pointer argument to an unspecified method.

    Published: 24 Feb 2013
    10
    Critical

    CVE-2013-0804

    Last Modified: 11 Apr 2025

    The client in Novell GroupWise 8.0 before 8.0.3 HP2 and 2012 before SP1 HP1 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect pointer dereference) via unspecified vectors.

    Published: 24 Feb 2013
    7.2
    High

    CVE-2013-1763

    Last Modified: 11 Apr 2025

    Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows local users to gain privileges via a large family value in a Netlink message.

    Published: 24 Feb 2013
    6.2
    Medium

    CVE-2013-1767

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.

    Published: 24 Feb 2013
    5
    Medium

    CVE-2013-0881

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via crafted data in the Matroska container format.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0885

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict API privileges during interaction with the Chrome Web Store, which has unspecified impact and attack vectors.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0886

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.99 on Mac OS X does not properly implement signal handling for Native Client (aka NaCl) code, which has unspecified impact and attack vectors.

    Published: 23 Feb 2013
    6.8
    Medium

    CVE-2013-0893

    Last Modified: 11 Apr 2025

    Race condition in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-2268

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the MathML implementation in WebKit in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, has unknown impact and remote attack vectors, related to a "high severity security issue."

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0882

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via a large number of SVG parameters.

    Published: 23 Feb 2013
    5
    Medium

    CVE-2013-0888

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a "user gesture check for dangerous file downloads."

    Published: 23 Feb 2013
    6.8
    Medium

    CVE-2013-0889

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly enforce a user gesture requirement before proceeding with a file download, which might make it easier for remote attackers to execute arbitrary code via a crafted file.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0890

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service (memory corruption) or possibly have other impact via unknown vectors.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0891

    Last Modified: 11 Apr 2025

    Integer overflow in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a blob.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0892

    Last Modified: 11 Apr 2025

    Multiple unspecified vulnerabilities in the IPC layer in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0896

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly manage memory during message handling for plug-ins, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 23 Feb 2013
    4.3
    Medium

    CVE-2013-0897

    Last Modified: 11 Apr 2025

    Off-by-one error in the PDF functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service via a crafted document.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0898

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving a URL.

    Published: 23 Feb 2013
    5
    Medium

    CVE-2013-0899

    Last Modified: 11 Apr 2025

    Integer overflow in the padding implementation in the opus_packet_parse_impl function in src/opus_decoder.c in Opus before 1.0.2, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (out-of-bounds read) via a long packet.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0879

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly implement web audio nodes, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0880

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to databases.

    Published: 23 Feb 2013
    5
    Medium

    CVE-2013-0883

    Last Modified: 11 Apr 2025

    Skia, as used in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service (incorrect read operation) via unspecified vectors.

    Published: 23 Feb 2013
    6.8
    Medium

    CVE-2013-0884

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly load Native Client (aka NaCl) code, which has unspecified impact and attack vectors.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0887

    Last Modified: 11 Apr 2025

    The developer-tools process in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, does not properly restrict privileges during interaction with a connected server, which has unspecified impact and attack vectors.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0894

    Last Modified: 11 Apr 2025

    Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other products, allows remote attackers to cause a denial of service (divide-by-zero error or out-of-bounds array access) or possibly have unspecified other impact via vectors involving a zero value for a bark map size.

    Published: 23 Feb 2013
    7.5
    High

    CVE-2013-0895

    Last Modified: 11 Apr 2025

    Google Chrome before 25.0.1364.97 on Linux, and before 25.0.1364.99 on Mac OS X, does not properly handle pathnames during copy operations, which might make it easier for remote attackers to execute arbitrary programs via unspecified vectors.

    Published: 23 Feb 2013
    5.8
    Medium

    CVE-2013-0253

    Last Modified: 11 Apr 2025

    The default configuration of Apache Maven 3.0.4, when using Maven Wagon 2.1, disables SSL certificate checks, which allows remote attackers to spoof servers via a man-in-the-middle (MITM) attack.

    Published: 23 Feb 2013
    7.8
    High

    CVE-2012-6326

    Last Modified: 11 Apr 2025

    VMware vCenter Server 4.1 before Update 3 and 5.0 before Update 2, and vCSA 5.0 before Update 2, allows remote attackers to cause a denial of service (disk consumption) via vectors that trigger large log entries.

    Published: 22 Feb 2013
    5.4
    Medium

    CVE-2013-0465

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the IBM WebSphere Cast Iron physical and virtual appliance 6.0 and 6.1 before 6.1.0.15 and 6.3 before 6.3.0.1, when LDAP authentication is enabled, allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vectors.

    Published: 22 Feb 2013
    7.6
    High

    CVE-2013-1659

    Last Modified: 11 Apr 2025

    VMware vCenter Server 4.0 before Update 4b, 5.0 before Update 2, and 5.1 before 5.1.0b; VMware ESXi 3.5 through 5.1; and VMware ESX 3.5 through 4.1 do not properly implement the Network File Copy (NFC) protocol, which allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption) by modifying the client-server data stream.

    Published: 22 Feb 2013
    4
    Medium

    CVE-2013-1772

    Last Modified: 11 Apr 2025

    The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.

    Published: 22 Feb 2013
    5
    Medium

    CVE-2013-1821

    Last Modified: 11 Apr 2025

    lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.

    Published: 22 Feb 2013
    2.1
    Low

    CVE-2013-0346

    Last Modified: 11 Apr 2025

    Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor has stated "The tomcat log directory does not contain any sensitive information."

    Published: 22 Feb 2013
    9
    Critical

    CVE-2013-0706

    Last Modified: 11 Apr 2025

    NEC Universal RAID Utility 1.40 Rev 680 and earlier, 2.31 Rev 1492 and earlier, and 2.5 Rev 2244 and earlier does not provide access control, which allows remote attackers to perform arbitrary RAID disk operations via unspecified vectors.

    Published: 22 Feb 2013
    4.3
    Medium

    CVE-2013-0730

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Newscoop 4.x through 4.1.0 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) language parameter to application/modules/admin/controllers/LanguagesController.php or (2) user parameter to application/modules/admin/controllers/UserController.php.

    Published: 22 Feb 2013
    4.3
    Medium

    CVE-2013-0471

    Last Modified: 11 Apr 2025

    The traditional scheduler in the client in IBM Tivoli Storage Manager (TSM) before 6.2.5.0, 6.3 before 6.3.1.0, and 6.4 before 6.4.0.1, when Prompted mode is enabled, allows remote attackers to cause a denial of service (scheduling outage) via unspecified vectors.

    Published: 21 Feb 2013
    5.1
    Medium

    CVE-2013-0472

    Last Modified: 11 Apr 2025

    The Web GUI in the client in IBM Tivoli Storage Manager (TSM) 6.3 before 6.3.1.0 and 6.4 before 6.4.0.1 allows man-in-the-middle attackers to obtain unspecified client access, and consequently obtain unspecified server access, via unknown vectors.

    Published: 21 Feb 2013
    6
    Medium

    CVE-2013-0477

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allow remote authenticated users to inject content, and conduct phishing attacks, via unspecified vectors.

    Published: 21 Feb 2013
    4
    Medium

    CVE-2013-0467

    Last Modified: 11 Apr 2025

    IBM Eclipse Help System (IEHS), as used in IBM Data Studio 3.1 and 3.1.1 and other products, allows remote authenticated users to read source code via a crafted URL.

    Published: 21 Feb 2013
    3.5
    Low

    CVE-2013-0478

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.0 and 10.1 before FP1 and InfoSphere Master Data Management Server for Product Information Management 6.0, 9.0, and 9.1 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

    Published: 21 Feb 2013
    6.8
    Medium

    CVE-2013-0900

    Last Modified: 11 Apr 2025

    Race condition in the International Components for Unicode (ICU) functionality in Google Chrome before 25.0.1364.97 on Windows and Linux, and before 25.0.1364.99 on Mac OS X, allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 21 Feb 2013
    7.5
    High

    CVE-2013-1362

    Last Modified: 11 Apr 2025

    Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.

    Published: 21 Feb 2013
    2.1
    Low

    CVE-2012-5509

    Last Modified: 11 Apr 2025

    aeolus-configserver-setup in the Aeolas Configuration Server, as used in Red Hat CloudForms Cloud Engine before 1.1.2, uses world-readable permissions for a temporary file in /tmp, which allows local users to read credentials by reading this file.

    Published: 21 Feb 2013
    1.9
    Low

    CVE-2013-0200

    Last Modified: 11 Apr 2025

    HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/hpcups_job#.out, (4) /tmp/hpijs_#####.out, or (5) /tmp/hpps_job#.out temporary file, a different vulnerability than CVE-2011-2722.

    Published: 21 Feb 2013
    6.2
    Medium

    CVE-2012-5536

    Last Modified: 11 Apr 2025

    A certain Red Hat build of the pam_ssh_agent_auth module on Red Hat Enterprise Linux (RHEL) 6 and Fedora Rawhide calls the glibc error function instead of the error function in the OpenSSH codebase, which allows local users to obtain sensitive information from process memory or possibly gain privileges via crafted use of an application that relies on this module, as demonstrated by su and sudo.

    Published: 21 Feb 2013
    2.1
    Low

    CVE-2012-6116

    Last Modified: 11 Apr 2025

    modules/certs/manifests/config.pp in katello-configure before 1.3.3.pulpv2 in Katello uses weak permissions (666) for the Candlepin bootstrap RPM, which allows local users to modify the Candlepin CA certificate by writing to this file.

    Published: 21 Feb 2013
    5.5
    Medium

    CVE-2012-6118

    Last Modified: 11 Apr 2025

    The Administer tab in Aeolus Conductor allows remote authenticated users to bypass intended quota restrictions by updating the Maximum Running Instances quota user setting.

    Published: 21 Feb 2013
    6.5
    Medium

    CVE-2012-6357

    Last Modified: 11 Apr 2025

    IBM Maximo Asset Management 7.5, Maximo Asset Management Essentials 7.5, and SmartCloud Control Desk 7.5 allow remote authenticated users to gain privileges and bypass intended restrictions on asset-lookup operations via unspecified vectors.

    Published: 20 Feb 2013
    6.5
    Medium

    CVE-2012-3321

    Last Modified: 11 Apr 2025

    IBM SmartCloud Control Desk 7.5 allows remote authenticated users to bypass intended access restrictions via vectors involving an expired password.

    Published: 20 Feb 2013
    4.3
    Medium

    CVE-2012-3328

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1, Maximo Asset Management Essentials 7.1, Tivoli Asset Management for IT 7.1 and 7.2, Tivoli Service Request Manager 7.1 and 7.2, and Change and Configuration Management Database (CCMDB) 7.1 and 7.2 allows remote attackers to inject arbitrary web script or HTML via vectors related to a hidden frame footer.

    Published: 20 Feb 2013