CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2013-1462

    Last Modified: 11 Apr 2025

    Integer signedness error in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to cause a denial of service (incorrect memory copy) via a SOAPAction header that lacks a " (double quote) character, a different vulnerability than CVE-2013-0230.

    Published: 31 Jan 2013
    7.6
    High

    CVE-2013-0930

    Last Modified: 11 Apr 2025

    Buffer overflow in Drive Control Program (DCP) in EMC AlphaStor 4.0 before build 814 allows remote attackers to execute arbitrary code via vectors involving a new device name.

    Published: 31 Jan 2013
    4.3
    Medium

    CVE-2012-0203

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Jan 2013
    9.3
    Critical

    CVE-2012-0204

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in InfoSphere Import Export Manager 8.1 through 9.1 in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 allows local users to gain privileges via a Trojan horse DLL in the current working directory.

    Published: 31 Jan 2013
    1.9
    Low

    CVE-2012-0700

    Last Modified: 11 Apr 2025

    The client in InfoSphere FastTrack 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly store credentials, which allows local users to bypass intended access restrictions via unspecified vectors.

    Published: 31 Jan 2013
    6.5
    Medium

    CVE-2012-0701

    Last Modified: 11 Apr 2025

    The client applications in the DataStage Administrator client in InfoSphere DataStage in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 rely on client-side access control, which allows remote authenticated users to gain privileges via unspecified vectors.

    Published: 31 Jan 2013
    4
    Medium

    CVE-2012-0702

    Last Modified: 11 Apr 2025

    Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly determine authorization, which allows remote authenticated users to gain privileges via unspecified vectors.

    Published: 31 Jan 2013
    1.9
    Low

    CVE-2012-4832

    Last Modified: 11 Apr 2025

    Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 and InfoSphere Business Glossary 8.1.1 and 8.1.2 does not have an off autocomplete attribute for the password field on the login page, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

    Published: 31 Jan 2013
    4.3
    Medium

    CVE-2013-1113

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cisco Unified Communications Domain Manager allows remote attackers to inject arbitrary web script or HTML via a crafted parameter value, aka Bug ID CSCue21042.

    Published: 31 Jan 2013
    7.1
    High

    CVE-2012-0705

    Last Modified: 11 Apr 2025

    InfoSphere Import Export Manager in InfoSphere Information Server MetaBrokers & Bridges (MBB) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, 8.7, and 9.1 does not validate unspecified input data, which allows remote authenticated users to execute arbitrary commands via unknown vectors.

    Published: 31 Jan 2013
    4.3
    Medium

    CVE-2012-4819

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in InfoSphere Business Glossary 8.1.1 and 8.1.2, InfoSphere DataStage Operation Console, InfoSphere Administration, and Reporting and Repository Management Web Console in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Jan 2013
    4.3
    Medium

    CVE-2012-6350

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web component in IBM Cognos TM1 before 9.5.2 FP3 and 10.1 before 10.1 FP1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 31 Jan 2013
    5
    Medium

    CVE-2013-1112

    Last Modified: 11 Apr 2025

    Cisco Carrier Routing System (CRS) allows remote attackers to cause a denial of service (packet loss) via short malformed packets that trigger inefficient processing, aka Bug ID CSCud79136.

    Published: 31 Jan 2013
    6.5
    Medium

    CVE-2012-0205

    Last Modified: 11 Apr 2025

    InfoSphere Metadata Workbench (MWB) 8.1 through 8.7 in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 does not properly restrict use of the troubleshooting feature, which allows remote authenticated users to bypass intended access restrictions or cause a denial of service (workbench outage) via unspecified vectors.

    Published: 31 Jan 2013
    5.8
    Medium

    CVE-2012-0703

    Last Modified: 11 Apr 2025

    Open redirect vulnerability in Information Services Framework (ISF) in IBM InfoSphere Information Server 8.1, 8.5 before FP3, and 8.7 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 31 Jan 2013
    4.3
    Medium

    CVE-2012-6029

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the web-authentication function on the Cisco NAC Appliance 4.9.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cm or (2) uri parameters to (a) perfigo_weblogin.jsp, or the (3) cm, (4) provider, (5) session, (6) uri, (7) userip, or (8) username parameters to (b) perfigo_cm_validate.jsp, aka Bug ID CSCud15109.

    Published: 31 Jan 2013
    5
    Medium

    CVE-2012-6522

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in the getContent function in codes/wcms.php in w-CMS 2.01 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter. NOTE: some of these details are obtained from third party information.

    Published: 31 Jan 2013
    7.5
    High

    CVE-2012-6526

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in show_code.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbitrary SQL commands via the code_id parameter.

    Published: 31 Jan 2013
    7.5
    High

    CVE-2010-5287

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in default.php in Cornerstone Technologies webConductor allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 Jan 2013
    4.3
    Medium

    CVE-2011-5255

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in admin/login in X3 CMS 0.4.3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) username, or (3) password parameter.

    Published: 31 Jan 2013
    7.5
    High

    CVE-2012-6525

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in members.php in PHPBridges allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 Jan 2013
    2.6
    Low

    CVE-2012-6527

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the My Calendar plugin before 1.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Published: 31 Jan 2013
    7.5
    High

    CVE-2012-6529

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in Marinet CMS allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) galleryphoto.php or (2) gallery.php; or the roomid parameter to (3) room.php or (4) room2.php.

    Published: 31 Jan 2013
    7.1
    High

    CVE-2012-6530

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users with the create folder permission to execute arbitrary code via a crafted request.

    Published: 31 Jan 2013
    7.5
    High

    CVE-2012-6524

    Last Modified: 11 Apr 2025

    SQL injection vulnerability in kommentar.php in pGB 2.12 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Published: 31 Jan 2013
    4.3
    Medium

    CVE-2012-6528

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 2.1 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) themes/default/tile_search/index.tmpl.php, (2) login.php, (3) search.php, (4) password_reminder.php, (5) login.php/jscripts/infusion, (6) login.php/mods/_standard/flowplayer, (7) browse.php/jscripts/infusion/framework/fss, (8) registration.php/themes/default/ie_styles.css, (9) about.php, or (10) themes/default/social/basic_profile.tmpl.php.

    Published: 31 Jan 2013
    4.3
    Medium

    CVE-2012-6523

    Last Modified: 11 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in w-CMS 2.01 allow remote attackers to inject arbitrary web script or HTML via (1) the p parameter in the getMenus function in codes/wcms.php; or the COMMENT parameter in (2) blog.php, (3) guestbook.php, or (4) forum.php in codes/. NOTE: some of these details are obtained from third party information.

    Published: 31 Jan 2013
    8.8
    High

    CVE-2013-0261

    Last Modified: 30 Apr 2026

    A flaw was found in PackStack. A local user could exploit a symlink attack on a temporary file with a predictable name in the `/tmp` directory. This vulnerability allows the local user to overwrite arbitrary files on the system, potentially leading to system compromise or data corruption.

    Published: 31 Jan 2013
    3.6
    Low

    CVE-2013-0164

    Last Modified: 11 Apr 2025

    The lockwrap function in port-proxy/bin/openshift-port-proxy-cfg in Red Hat OpenShift Origin before 1.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with a predictable name in /tmp.

    Published: 31 Jan 2013
    6.9
    Medium

    CVE-2012-5660

    Last Modified: 11 Apr 2025

    abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."

    Published: 30 Jan 2013
    5.1
    Medium

    CVE-2013-0213

    Last Modified: 11 Apr 2025

    The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.

    Published: 30 Jan 2013
    2.1
    Low

    CVE-2013-0218

    Last Modified: 11 Apr 2025

    The GUI installer in JBoss Enterprise Application Platform (EAP) and Enterprise Web Platform (EWP) 5.2.0 and possibly 5.1.2 uses world-readable permissions for the auto-install XML file, which allows local users to obtain the administrator password and the sucker password by reading this file.

    Published: 30 Jan 2013
    3.7
    Low

    CVE-2012-5659

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in plugins/abrt-action-install-debuginfo-to-abrt-cache.c in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to load and execute arbitrary Python modules by modifying the PYTHONPATH environment variable to reference a malicious Python module.

    Published: 30 Jan 2013
    5.1
    Medium

    CVE-2013-0214

    Last Modified: 11 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to hijack the authentication of arbitrary users by leveraging knowledge of a password and composing requests that perform SWAT actions.

    Published: 30 Jan 2013
    4
    Medium

    CVE-2013-1450

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not properly reuse TCP sessions to the proxy server, which allows remote attackers to obtain sensitive information intended for a specific host via a crafted HTML document that triggers many HTTPS requests and then triggers an HTTP request to that host, as demonstrated by reading a Cookie header, aka MSRC 12096gd.

    Published: 29 Jan 2013
    4
    Medium

    CVE-2013-1451

    Last Modified: 11 Apr 2025

    Microsoft Internet Explorer 8 and 9, when the Proxy Settings configuration has the same Proxy address and Port values in the HTTP and Secure rows, does not ensure that the SSL lock icon is consistent with the Address bar, which makes it easier for remote attackers to spoof web sites via a crafted HTML document that triggers many HTTPS requests to an arbitrary host, followed by an HTTPS request to a trusted host and then an HTTP request to an untrusted host, a related issue to CVE-2013-1450.

    Published: 29 Jan 2013
    6.8
    Medium

    CVE-2013-0949

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

    Published: 29 Jan 2013
    6.8
    Medium

    CVE-2013-0953

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

    Published: 29 Jan 2013
    6.8
    Medium

    CVE-2013-0959

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

    Published: 29 Jan 2013
    6.8
    Medium

    CVE-2013-0954

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

    Published: 29 Jan 2013
    6.8
    Medium

    CVE-2013-0948

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

    Published: 29 Jan 2013
    6.8
    Medium

    CVE-2013-0951

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

    Published: 29 Jan 2013
    6.8
    Medium

    CVE-2013-0952

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

    Published: 29 Jan 2013
    6.8
    Medium

    CVE-2013-0955

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

    Published: 29 Jan 2013
    6.8
    Medium

    CVE-2013-0956

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

    Published: 29 Jan 2013
    6.8
    Medium

    CVE-2013-0958

    Last Modified: 11 Apr 2025

    WebKit, as used in Apple iOS before 6.1, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2013-01-28-1.

    Published: 29 Jan 2013
    2.6
    Low

    CVE-2013-0962

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WebKit in Apple iOS before 6.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via crafted content that is not properly handled during a copy-and-paste operation.

    Published: 29 Jan 2013
    2.1
    Low

    CVE-2013-0963

    Last Modified: 11 Apr 2025

    Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID certificates, which might allow physically proximate attackers to bypass authentication by leveraging an incorrect assignment of an empty string value to an AppleID.

    Published: 29 Jan 2013
    3.6
    Low

    CVE-2013-0964

    Last Modified: 11 Apr 2025

    The kernel in Apple iOS before 6.1 and Apple TV before 5.2 does not properly validate copyin and copyout arguments, which allows local users to bypass intended pointer restrictions and access locations in the first kernel-memory page by specifying a length of less than one page.

    Published: 29 Jan 2013
    5.1
    Medium

    CVE-2013-0974

    Last Modified: 11 Apr 2025

    StoreKit in Apple iOS before 6.1 does not properly handle the disabling of JavaScript within the preferences configuration of Mobile Safari, which allows remote attackers to bypass intended access restrictions and execute JavaScript code via a web site with a Smart App Banner.

    Published: 29 Jan 2013