CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2013-0388

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft HRMS component in Oracle PeopleSoft Products 9.1 allows remote attackers to affect integrity via unknown vectors related to Mobile Company Directory.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0392

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote attackers to affect integrity via unknown vectors related to Portal, a different vulnerability than CVE-2012-5059.

    Published: 17 Jan 2013
    6.8
    Medium

    CVE-2013-0393

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 and 8.4 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2013-0418.

    Published: 17 Jan 2013
    5
    Medium

    CVE-2013-0394

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft HRMS component in Oracle PeopleSoft Products 9.0 and 9.1 allows remote attackers to affect confidentiality via unknown vectors related to Candidate Gateway.

    Published: 17 Jan 2013
    4
    Medium

    CVE-2013-0395

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect integrity via unknown vectors related to Security.

    Published: 17 Jan 2013
    5
    Medium

    CVE-2013-0396

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Application Performance Management (APM) component in Oracle Enterprise Manager Grid Control 6.5, 11.1, and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Business Transaction Management, a different vulnerability than CVE-2013-0360.

    Published: 17 Jan 2013
    6.4
    Medium

    CVE-2013-0397

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Diagnostics.

    Published: 17 Jan 2013
    4.6
    Medium

    CVE-2013-0407

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 and 11 allows local users to affect availability via unknown vectors related to Kernel/DTrace Framework.

    Published: 17 Jan 2013
    3.3
    Low

    CVE-2013-0414

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect integrity and availability via unknown vectors related to Utility/ksh93.

    Published: 17 Jan 2013
    6
    Medium

    CVE-2013-0415

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Bind/Postinstall script for Bind package.

    Published: 17 Jan 2013
    2.4
    Low

    CVE-2013-0420

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core. NOTE: The previous information was obtained from the January 2013 Oracle CPU. Oracle has not commented on claims from another vendor that this issue is related to an incorrect comparison in the vga_draw_text function in Devices/Graphics/DevVGA.cpp, which can cause VirtualBox to "draw more lines than necessary."

    Published: 17 Jan 2013
    4
    Medium

    CVE-2012-3172

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote authenticated users to affect availability via unknown vectors related to Siebel Apps - Multi-channel Technologies.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2012-5062

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote attackers to affect integrity via unknown vectors related to User Interface Framework.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0352

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1 and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Content Management.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0358

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1 and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Resource Manager.

    Published: 17 Jan 2013
    5
    Medium

    CVE-2013-0360

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Application Performance Management (APM) component in Oracle Enterprise Manager Grid Control 6.5, 11.1, and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Business Transaction Management, a different vulnerability than CVE-2013-0396.

    Published: 17 Jan 2013
    10
    Critical

    CVE-2013-0361

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2013-0366.

    Published: 17 Jan 2013
    5.5
    Medium

    CVE-2013-0369

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.51 and 8.52 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Query.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0372

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 11.1.0.1 and 12.1.0.1; EM DB Control 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Distributed/Cross DB Features.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0374

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control EM Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.1, and 12.1.0.2 allows remote attackers to affect integrity via unknown vectors related to Database Cloning.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0376

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Diagnostics.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2013-0380

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Payroll component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to View Payslip.

    Published: 17 Jan 2013
    6.4
    Medium

    CVE-2013-0381

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Application Framework.

    Published: 17 Jan 2013
    5.5
    Medium

    CVE-2013-0391

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the PeopleSoft PeopleTools component in Oracle PeopleSoft Products 8.52 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Security.

    Published: 17 Jan 2013
    6.6
    Medium

    CVE-2013-0400

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Sun Solaris 9 and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to Filesystem/cachefs.

    Published: 17 Jan 2013
    3.5
    Low

    CVE-2012-1678

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the JD Edwards EnterpriseOne Tools component in Oracle JD Edwards Products 8.98, 9.1, and 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC.

    Published: 17 Jan 2013
    5
    Medium

    CVE-2012-3169

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Siebel CRM component in Oracle Siebel CRM 8.1.1 and 8.2.2 allows remote attackers to affect availability via unknown vectors related to Siebel Core - Server Infrastructure, a different vulnerability than CVE-2012-3170.

    Published: 17 Jan 2013
    2.1
    Low

    CVE-2012-3178

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the kernel in Oracle Sun Solaris 11 allows local users to affect availability via unknown vectors.

    Published: 17 Jan 2013
    9
    Critical

    CVE-2012-3220

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Spatial component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users with Create Session privileges to affect confidentiality, integrity, and availability via unknown vectors.

    Published: 17 Jan 2013
    4.3
    Medium

    CVE-2012-5097

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Oracle Access Manager component in Oracle Fusion Middleware 10.1.4.3.0, 11.1.1.5.0, and 11.1.2.0.0 allows remote attackers to affect integrity, related to OAM Webgate.

    Published: 17 Jan 2013
    9.8
    Critical

    CVE-2013-0632

    Last Modified: 21 Apr 2026

    administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

    Published: 17 Jan 2013
    4.9
    Medium

    CVE-2013-0190

    Last Modified: 11 Apr 2025

    The xen_failsafe_callback function in Xen for the Linux kernel 2.6.23 and other versions, when running a 32-bit PVOPS guest, allows local users to cause a denial of service (guest crash) by triggering an iret fault, leading to use of an incorrect stack pointer and stack corruption.

    Published: 16 Jan 2013
    4.3
    Medium

    CVE-2013-4201

    Last Modified: 21 Nov 2024

    Katello allows remote authenticated users to call the "system remove_deletion" CLI command via vectors related to "remove system" permissions.

    Published: 16 Jan 2013
    5
    Medium

    CVE-2013-0833

    Last Modified: 11 Apr 2025

    Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to printing.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2012-5149

    Last Modified: 11 Apr 2025

    Integer overflow in the audio IPC layer in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2012-5145

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG layout.

    Published: 15 Jan 2013
    5
    Medium

    CVE-2012-5146

    Last Modified: 11 Apr 2025

    Google Chrome before 24.0.1312.52 allows remote attackers to bypass the Same Origin Policy via a malformed URL.

    Published: 15 Jan 2013
    6.8
    Medium

    CVE-2012-5151

    Last Modified: 11 Apr 2025

    Integer overflow in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code in a PDF document.

    Published: 15 Jan 2013
    5
    Medium

    CVE-2012-5152

    Last Modified: 11 Apr 2025

    Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors involving seek operations on video data.

    Published: 15 Jan 2013
    5
    Medium

    CVE-2012-5155

    Last Modified: 11 Apr 2025

    Google Chrome before 24.0.1312.52 on Mac OS X does not use an appropriate sandboxing approach for worker processes, which makes it easier for remote attackers to bypass intended access restrictions via unspecified vectors.

    Published: 15 Jan 2013
    6.8
    Medium

    CVE-2012-5156

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving PDF fields.

    Published: 15 Jan 2013
    4.3
    Medium

    CVE-2012-5157

    Last Modified: 11 Apr 2025

    Google Chrome before 24.0.1312.52 does not properly handle image data in PDF documents, which allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted document.

    Published: 15 Jan 2013
    6.8
    Medium

    CVE-2013-0828

    Last Modified: 11 Apr 2025

    The PDF functionality in Google Chrome before 24.0.1312.52 does not properly perform a cast of an unspecified variable during processing of the root of the structure tree, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document.

    Published: 15 Jan 2013
    6.4
    Medium

    CVE-2013-0829

    Last Modified: 11 Apr 2025

    Google Chrome before 24.0.1312.52 does not properly maintain database metadata, which allows remote attackers to bypass intended file-access restrictions via unspecified vectors.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2013-0830

    Last Modified: 11 Apr 2025

    The IPC layer in Google Chrome before 24.0.1312.52 on Windows omits a NUL character required for termination of an unspecified data structure, which has unknown impact and attack vectors.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2013-0831

    Last Modified: 11 Apr 2025

    Directory traversal vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to have an unspecified impact by leveraging access to an extension process.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2013-0832

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to printing.

    Published: 15 Jan 2013
    5
    Medium

    CVE-2013-0835

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in the Geolocation implementation in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service (application crash) via unknown vectors.

    Published: 15 Jan 2013
    6.8
    Medium

    CVE-2013-0836

    Last Modified: 11 Apr 2025

    Google V8 before 3.14.5.3, as used in Google Chrome before 24.0.1312.52, does not properly implement garbage collection, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaScript code.

    Published: 15 Jan 2013
    7.5
    High

    CVE-2013-0837

    Last Modified: 11 Apr 2025

    Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of extension tabs.

    Published: 15 Jan 2013