CVE Feed

    Dashboard / CVE

    6.4
    Medium

    CVE-2013-3221

    Last Modified: 11 Apr 2025

    The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.

    Published: 7 Feb 2013
    7.5
    High

    CVE-2013-1635

    Last Modified: 11 Apr 2025

    ext/soap/soap.c in PHP before 5.3.22 and 5.4.x before 5.4.13 does not validate the relationship between the soap.wsdl_cache_dir directive and the open_basedir directive, which allows remote attackers to bypass intended access restrictions by triggering the creation of cached SOAP WSDL files in an arbitrary directory.

    Published: 7 Feb 2013
    4.3
    Medium

    CVE-2012-1064

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Feb 2013
    7.5
    High

    CVE-2012-2292

    Last Modified: 11 Apr 2025

    The Silverlight cross-domain policy in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 does not restrict access to the Archer application, which allows remote attackers to bypass the Same Origin Policy via unspecified vectors.

    Published: 6 Feb 2013
    4.3
    Medium

    CVE-2012-3279

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in HP Network Node Manager i (NNMi) 8.x, 9.0x, 9.1x, and 9.20 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Feb 2013
    7.8
    High

    CVE-2012-3281

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Device Manager in HP XP P9000 Command View Advanced Edition before 7.4.0-00 allows remote attackers to cause a denial of service via unknown vectors.

    Published: 6 Feb 2013
    10
    Critical

    CVE-2012-3282

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1468.

    Published: 6 Feb 2013
    10
    Critical

    CVE-2012-3283

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1511.

    Published: 6 Feb 2013
    10
    Critical

    CVE-2012-3284

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1512.

    Published: 6 Feb 2013
    4.3
    Medium

    CVE-2012-5186

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in FLUGELz netmania myu-s and PHP WeblogSystem allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 6 Feb 2013
    4.3
    Medium

    CVE-2012-5187

    Last Modified: 11 Apr 2025

    The Weathernews Touch application 2.3.2 and earlier for Android allows attackers to obtain sensitive information about logged locations via a crafted application that leverages read permission for system log files.

    Published: 6 Feb 2013
    4
    Medium

    CVE-2013-1107

    Last Modified: 11 Apr 2025

    The search function in Cisco Webex Social (formerly Cisco Quad) allows remote authenticated users to read files via unspecified parameters, aka Bug ID CSCud40235.

    Published: 6 Feb 2013
    6.8
    Medium

    CVE-2013-1120

    Last Modified: 11 Apr 2025

    Multiple cross-site request forgery (CSRF) vulnerabilities on the Cisco Unity Express with software before 8.0 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCue35910.

    Published: 6 Feb 2013
    6.8
    Medium

    CVE-2012-2294

    Last Modified: 11 Apr 2025

    EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allow remote attackers to conduct clickjacking attacks via a crafted web page.

    Published: 6 Feb 2013
    6.5
    Medium

    CVE-2012-2293

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in EMC RSA Archer SmartSuite Framework 4.x and RSA Archer GRC 5.x before 5.2SP1 allows remote authenticated users to upload files, and consequently execute arbitrary code, via a relative path.

    Published: 6 Feb 2013
    10
    Critical

    CVE-2012-3285

    Last Modified: 11 Apr 2025

    Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1513.

    Published: 6 Feb 2013
    7.5
    High

    CVE-2010-5107

    Last Modified: 29 May 2026

    The default configuration of OpenSSH through 6.1 enforces a fixed time limit between establishing a TCP connection and completing a login, which makes it easier for remote attackers to cause a denial of service (connection-slot exhaustion) by periodically making many new TCP connections.

    Published: 6 Feb 2013
    7.5
    High

    CVE-2013-0249

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the realm parameter in a (1) POP3, (2) SMTP or (3) IMAP message.

    Published: 6 Feb 2013
    4.3
    Medium

    CVE-2013-0256

    Last Modified: 11 Apr 2025

    darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.

    Published: 6 Feb 2013
    7.5
    High

    CVE-2013-0264

    Last Modified: 21 Nov 2024

    An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a system support it.

    Published: 6 Feb 2013
    5.8
    Medium

    CVE-2014-0363

    Last Modified: 12 Apr 2025

    The ServerTrustManager component in the Ignite Realtime Smack XMPP API before 4.0.0-rc1 does not verify basicConstraints and nameConstraints in X.509 certificate chains from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate chain.

    Published: 6 Feb 2013
    4.3
    Medium

    CVE-2013-0176

    Last Modified: 11 Apr 2025

    The publickey_from_privatekey function in libssh before 0.5.4, when no algorithm is matched during negotiations, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a "Client: Diffie-Hellman Key Exchange Init" packet.

    Published: 5 Feb 2013
    7.1
    High

    CVE-2011-1350

    Last Modified: 11 Apr 2025

    The PowerVR SGX driver in Android before 2.3.6 allows attackers to obtain potentially sensitive information from kernel stack memory via an application that uses a crafted length parameter in a request to the pvrsrvkm device.

    Published: 5 Feb 2013
    6.9
    Medium

    CVE-2011-1352

    Last Modified: 11 Apr 2025

    The PowerVR SGX driver in Android before 2.3.6 allows attackers to gain root privileges via an application that triggers kernel memory corruption using crafted user data to the pvrsrvkm device.

    Published: 5 Feb 2013
    5
    Medium

    CVE-2013-0166

    Last Modified: 11 Apr 2025

    OpenSSL before 0.9.8y, 1.0.0 before 1.0.0k, and 1.0.1 before 1.0.1d does not properly perform signature verification for OCSP responses, which allows remote OCSP servers to cause a denial of service (NULL pointer dereference and application crash) via an invalid key.

    Published: 5 Feb 2013
    5.2
    Medium

    CVE-2013-0217

    Last Modified: 11 Apr 2025

    Memory leak in drivers/net/xen-netback/netback.c in the Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (memory consumption) by triggering certain error conditions.

    Published: 5 Feb 2013
    4.9
    Medium

    CVE-2013-0231

    Last Modified: 11 Apr 2025

    The pciback_enable_msi function in the PCI backend driver (drivers/xen/pciback/conf_space_capability_msi.c) in Xen for the Linux kernel 2.6.18 and 3.8 allows guest OS users with PCI device access to cause a denial of service via a large number of kernel log messages. NOTE: some of these details are obtained from third party information.

    Published: 5 Feb 2013
    5
    Medium

    CVE-2013-0247

    Last Modified: 11 Apr 2025

    OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of log entries.

    Published: 5 Feb 2013
    2.1
    Low

    CVE-2013-2547

    Last Modified: 11 Apr 2025

    The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NET_ADMIN capability.

    Published: 5 Feb 2013
    5
    Medium

    CVE-2012-2686

    Last Modified: 11 Apr 2025

    crypto/evp/e_aes_cbc_hmac_sha1.c in the AES-NI functionality in the TLS 1.1 and 1.2 implementations in OpenSSL 1.0.1 before 1.0.1d allows remote attackers to cause a denial of service (application crash) via crafted CBC data.

    Published: 5 Feb 2013
    5.2
    Medium

    CVE-2013-0216

    Last Modified: 11 Apr 2025

    The Xen netback functionality in the Linux kernel before 3.7.8 allows guest OS users to cause a denial of service (loop) by triggering ring pointer corruption.

    Published: 5 Feb 2013
    4.7
    Medium

    CVE-2013-0153

    Last Modified: 11 Apr 2025

    The AMD IOMMU support in Xen 4.2.x, 4.1.x, 3.3, and other versions, when using AMD-Vi for PCI passthrough, uses the same interrupt remapping table for the host and all guests, which allows guests to cause a denial of service by injecting an interrupt into other guests.

    Published: 5 Feb 2013
    4.3
    Medium

    CVE-2013-0215

    Last Modified: 11 Apr 2025

    oxenstored in Xen 4.1.x, Xen 4.2.x, and xen-unstable does not properly consider the state of the Xenstore ring during read operations, which allows guest OS users to cause a denial of service (daemon crash and host-control outage, or memory consumption) or obtain sensitive control-plane data by leveraging guest administrative access.

    Published: 5 Feb 2013
    3.6
    Low

    CVE-2013-0254

    Last Modified: 11 Apr 2025

    The QSharedMemory class in Qt 5.0.0, 4.8.x before 4.8.5, 4.7.x before 4.7.6, and other versions including 4.4.0 uses weak permissions (world-readable and world-writable) for shared memory segments, which allows local users to read sensitive information or modify critical program data, as demonstrated by reading a pixmap being sent to an X server.

    Published: 5 Feb 2013
    2.1
    Low

    CVE-2013-2546

    Last Modified: 11 Apr 2025

    The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack memory by leveraging the CAP_NET_ADMIN capability.

    Published: 5 Feb 2013
    2.1
    Low

    CVE-2013-2548

    Last Modified: 11 Apr 2025

    The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value during a copy operation, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.

    Published: 5 Feb 2013
    4.3
    Medium

    CVE-2013-1471

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in admin/FEAdmin.html in Fortinet FortiMail before 4.3.4 on FortiMail Identity-Based Encryption (IBE) appliances allow user-assisted remote attackers to inject arbitrary web script or HTML via (1) the Add field for the Black List under Antispam Management User Preferences or (2) the User name field for the Personal Black/White List in the AntiSpam section.

    Published: 4 Feb 2013
    4
    Medium

    CVE-2013-1619

    Last Modified: 11 Apr 2025

    The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

    Published: 4 Feb 2013
    4
    Medium

    CVE-2013-1624

    Last Modified: 12 May 2025

    The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

    Published: 4 Feb 2013
    4.3
    Medium

    CVE-2013-4346

    Last Modified: 12 Apr 2025

    The Server.verify_request function in SimpleGeo python-oauth2 does not check the nonce, which allows remote attackers to perform replay attacks via a signed URL.

    Published: 4 Feb 2013
    7.5
    High

    CVE-2012-5629

    Last Modified: 11 Apr 2025

    The default configuration of the (1) LdapLoginModule and (2) LdapExtLoginModule modules in JBoss Enterprise Application Platform (EAP) 4.3.0 CP10, 5.2.0, and 6.0.1, and Enterprise Web Platform (EWP) 5.2.0 allow remote attackers to bypass authentication via an empty password.

    Published: 4 Feb 2013
    4
    Medium

    CVE-2013-0168

    Last Modified: 11 Apr 2025

    The MoveDisk command in Red Hat Enterprise Virtualization Manager (RHEV-M) 3.1 and earlier does not properly check permissions on storage domains, which allows remote authenticated storage admins to cause a denial of service (free space consumption of other storage domains) via unspecified vectors.

    Published: 4 Feb 2013
    4.3
    Medium

    CVE-2013-1623

    Last Modified: 11 Apr 2025

    The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

    Published: 4 Feb 2013
    2.6
    Low

    CVE-2013-0169

    Last Modified: 11 Apr 2025

    The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

    Published: 4 Feb 2013
    4.3
    Medium

    CVE-2013-1620

    Last Modified: 11 Apr 2025

    The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

    Published: 4 Feb 2013
    5
    Medium

    CVE-2012-6352

    Last Modified: 11 Apr 2025

    The Session Manager in IBM Sterling Connect:Direct through 4.1.0.3 on UNIX allows remote attackers to cause a denial of service (daemon crash and disk consumption) via crafted data.

    Published: 2 Feb 2013
    7.6
    High

    CVE-2012-1543

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU. NOTE: the previous information is from the February 2013 CPU. Oracle has not commented on claims from a third party that the issue is due to an invalid type cast in the JSObject class.

    Published: 2 Feb 2013
    10
    Critical

    CVE-2013-0436

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU.

    Published: 2 Feb 2013
    10
    Critical

    CVE-2013-0439

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU.

    Published: 2 Feb 2013
    10
    Critical

    CVE-2013-0447

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the February 2013 CPU.

    Published: 2 Feb 2013