7.5
    High

    CVE-2013-6829

    Last Modified: 6 Dec 2013

    admin/confnetworking.html in PineApp Mail-SeCure allows remote attackers to execute arbitrary commands via shell metacharacters in the pinghost parameter during a ping operation.

    Source:Ruben Garrote García
    Published:20 Nov 2013
    6.8
    Medium

    CVE-2013-6826

    Last Modified: 30 Nov 2015

    cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site request forgery (CSRF) attacks.

    Source:William Costa
    Published:19 Nov 2013
    10
    Critical

    CVE-2013-6810

    Last Modified: 13 Sept 2017

    The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Network Advisor, and possibly other products, allows remote attackers to execute arbitrary code by using a servlet to upload an executable file.

    Source:James Fitts
    Published:12 Dec 2013
    4.7
    Medium

    CVE-2013-6799

    Last Modified: 8 Apr 2014

    Apple Mac OS X 10.9 allows local users to cause a denial of service (memory corruption or panic) by creating a hard link to a directory. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-0105.

    Source:Maksymilian Arciemowicz
    Published:16 Nov 2013
    6.8
    Medium

    CVE-2013-6797

    Last Modified: 2 Dec 2015

    Cross-site request forgery (CSRF) vulnerability in bluewrench-video-widget.php in the Blue Wrench Video Widget plugin before 2.0.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that embed arbitrary URLs via the bw_url parameter in the bw-videos page to wp-admin/admin.php, as demonstrated by embedding a URL to a JavaScript file.

    Source:Haider Mahmood
    Published:15 Nov 2013
    5
    Medium

    CVE-2013-6796

    Last Modified: 21 Nov 2013

    The SMTP server in DeepOfix 3.3 and earlier allows remote attackers to bypass authentication via an empty password, which triggers an LDAP anonymous bind.

    Source:Gerardo Vazquez_ Eduardo Arriols
    Published:26 Oct 2014
    4.3
    Medium

    CVE-2013-6794

    Last Modified: 31 Oct 2013

    Cross-site scripting (XSS) vulnerability in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allows remote attackers to inject arbitrary web script or HTML via the Location field. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Vulnerability-Lab
    Published:14 Nov 2013
    4.3
    Medium

    CVE-2013-6793

    Last Modified: 31 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in the Calendar module in Olat 7.8.0.1 (b20130821 N1) allow remote attackers to inject arbitrary web script or HTML via the (1) event name or (2) date field.

    Source:Vulnerability-Lab
    Published:14 Nov 2013
    9.8
    Critical

    CVE-2013-6792

    Last Modified: 27 Nov 2015

    Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability

    Source:Jay Freeman
    Published:23 Jan 2020
    6
    Medium

    CVE-2013-6787

    Last Modified: 3 Dec 2013

    SQL injection vulnerability in the check_user_password function in main/auth/profile.php in Chamilo LMS 1.9.6 and earlier, when using the non-encrypted passwords mode set at installation, allows remote authenticated users to execute arbitrary SQL commands via the "password0" parameter.

    Source:High-Tech Bridge SA
    Published:5 Dec 2013
    7.2
    High

    CVE-2013-6767

    Last Modified: 17 Dec 2013

    Stack-based buffer overflow in pepoly.dll in Quick Heal AntiVirus Pro 7.0.0.1 allows local users to execute arbitrary code or cause a denial of service (process crash) via a long *.text value in a PE file.

    Source:Arash Allebrahim
    Published:20 Dec 2013
    7.5
    High

    CVE-2013-6765

    Last Modified: 21 Jul 2014

    OpenVAS Manager 3.0 before 3.0.7 and 4.0 before 4.0.4 allows remote attackers to bypass the OMP authentication restrictions and execute OMP commands via a crafted OMP request for version information, which causes the state to be set to CLIENT_AUTHENTIC, as demonstrated by the omp_xml_handle_end_element function in omp.c.

    Source:EccE
    Published:19 May 2014
    5.5
    Medium

    CVE-2013-6720

    Last Modified: 26 Mar 2014

    Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.

    Source:drone
    Published:6 Mar 2014
    6
    Medium

    CVE-2013-6719

    Last Modified: 26 Mar 2014

    delivery.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the testconn_host parameter.

    Source:drone
    Published:6 Mar 2014
    4.3
    Medium

    CVE-2013-6674

    Last Modified: 27 Jan 2014

    Cross-site scripting (XSS) vulnerability in Mozilla Thunderbird 17.x through 17.0.8, Thunderbird ESR 17.x through 17.0.10, and SeaMonkey before 2.20 allows user-assisted remote attackers to inject arbitrary web script or HTML via an e-mail message containing a data: URL in an IFRAME element, a related issue to CVE-2014-2018.

    Source:Vulnerability-Lab
    Published:6 Feb 2014
    7.5
    High

    CVE-2013-6668

    Last Modified: 12 Apr 2025

    Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome before 33.0.1750.146, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.

    Published:18 Feb 2014
    5
    Medium

    CVE-2013-6627

    Last Modified: 19 Dec 2016

    net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1xx) status codes, which allows remote web servers to cause a denial of service (out-of-bounds read) via a crafted response.

    Source:Skylined
    Published:13 Nov 2013
    9
    Critical

    CVE-2013-6618

    Last Modified: 25 Nov 2013

    jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to execute arbitrary commands via the rsargs parameter in an exec action.

    Source:Sense of Security
    Published:5 Nov 2013
    5.8
    Medium

    CVE-2013-6492

    Last Modified: 24 Dec 2015

    The Piranha Configuration Tool in Piranha 0.8.6 does not properly restrict access to webpages, which allows remote attackers to bypass authentication and read or modify the LVS configuration via an HTTP POST request.

    Source:Andreas Schiermeier
    Published:11 Dec 2013
    10
    Critical

    CVE-2013-6490

    Last Modified: 11 Apr 2025

    The SIMPLE protocol functionality in Pidgin before 2.10.8 allows remote attackers to have an unspecified impact via a negative Content-Length header, which triggers a buffer overflow.

    Published:28 Jan 2014
    2.1
    Low

    CVE-2013-6480

    Last Modified: 12 Dec 2015

    Libcloud 0.12.3 through 0.13.2 does not set the scrub_data parameter for the destroy DigitalOcean API, which allows local users to obtain sensitive information by leveraging a new VM.

    Source:anonymous
    Published:7 Jan 2014
    5.4
    Medium

    CVE-2013-6465

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.

    Published:6 Feb 2014
    7.5
    High

    CVE-2013-6420

    Last Modified: 17 Dec 2013

    The asn1_time_to_time_t function in ext/openssl/openssl.c in PHP before 5.3.28, 5.4.x before 5.4.23, and 5.5.x before 5.5.7 does not properly parse (1) notBefore and (2) notAfter timestamps in X.509 certificates, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted certificate that is not properly handled by the openssl_x509_parse function.

    Source:Stefan Esser
    Published:10 Dec 2013
    7.9
    High

    CVE-2013-6375

    Last Modified: 11 Apr 2025

    Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter."

    Published:20 Nov 2013
    6.5
    Medium

    CVE-2013-6366

    Last Modified: 14 Oct 2013

    The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().exec call.

    Source:Metasploit
    Published:4 Nov 2013
    8.8
    High

    CVE-2013-6364

    Last Modified: 8 Nov 2013

    Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

    Source:Marcela Benetrix
    Published:5 Nov 2019
    6.8
    Medium

    CVE-2013-6357

    Last Modified: 6 Nov 2013

    Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator.

    Source:Ivano Binetti
    Published:4 Nov 2013
    Low

    CVE-2013-6356

    Last Modified: 18 Nov 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue because of dependency on the victim's direct involvement in modifying the Windows registry to enable the attack. Notes: none

    Source:Julien Ahrens
    Published:9 Dec 2013
    10
    Critical

    CVE-2013-6343

    Last Modified: 4 Dec 2016

    Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp.

    Source:Jacob Holcomb
    Published:22 Jan 2014
    7.5
    High

    CVE-2013-6341

    Last Modified: 3 Dec 2013

    SQL injection vulnerability in Dokeos 2.2 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the language parameter to index.php.

    Source:High-Tech Bridge SA
    Published:5 Dec 2013
    7.5
    High

    CVE-2013-6283

    Last Modified: 19 Aug 2013

    VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a URL in a m3u file.

    Source:Asesino04
    Published:25 Oct 2013
    8.8
    High

    CVE-2013-6282

    Last Modified: 29 Dec 2016

    The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

    Source:Metasploit
    Published:19 Nov 2013
    6.5
    Medium

    CVE-2013-6275

    Last Modified: 29 Oct 2013

    Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.

    Source:Marcela Benetrix
    Published:5 Nov 2019
    5
    Medium

    CVE-2013-6246

    Last Modified: 25 Nov 2015

    The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full name) by sending a login request with a valid domain and username but without the CaptchaType, UseCaptchaEveryTime, and CaptchaResponse parameters.

    Source:Johnny Bravo
    Published:24 Oct 2013
    9.8
    Critical

    CVE-2013-6236

    Last Modified: 5 Nov 2013

    IZON IP 2.0.2: hard-coded password vulnerability

    Source:Mark Stanislav
    Published:12 Feb 2020
    8
    High

    CVE-2013-6234

    Last Modified: 3 Mar 2014

    Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory, aka "XSS File Upload."

    Source:Christian Catalano
    Published:22 Nov 2019
    4.3
    Medium

    CVE-2013-6233

    Last Modified: 3 Mar 2014

    Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via the Description field in the "Short document metadata."

    Source:Christian Catalano
    Published:7 Mar 2014
    3.5
    Low

    CVE-2013-6232

    Last Modified: 3 Mar 2014

    Cross-site scripting (XSS) vulnerability in SpagoBI before 4.1 allows remote authenticated users to inject arbitrary web script or HTML via a document note in the execution page.

    Source:Christian Catalano
    Published:7 Mar 2014
    8.8
    High

    CVE-2013-6231

    Last Modified: 28 Feb 2014

    SpagoBI before 4.1 has Privilege Escalation via an error in the AdapterHTTP script

    Source:Christian Catalano
    Published:10 Jan 2020
    4.3
    Medium

    CVE-2013-6229

    Last Modified: 23 Dec 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Atmail Webmail Server 7.0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) filter parameter to index.php/mail/mail/listfoldermessages/searching/true/selectFolder/INBOX/resultContext/searchResultsTab5 or (2) mailId[] parameter to index.php/mail/mail/movetofolder/fromFolder/INBOX/toFolder/INBOX.Trash. NOTE: the view attachment message process vector is already covered by CVE-2013-2585.

    Source:Vicente Aguilera Diaz
    Published:12 Feb 2014
    7.5
    High

    CVE-2013-6227

    Last Modified: 17 Mar 2019

    Unrestricted file upload vulnerability in plugins/editor.zoho/agent/save_zoho.php in the Zoho plugin in Pydio (formerly AjaXplorer) before 5.0.4 allows remote attackers to execute arbitrary code by uploading an executable file, and then accessing this file at a location specified by the format parameter of a move operation.

    Source:_jazz______
    Published:27 Dec 2014
    9.8
    Critical

    CVE-2013-6225

    Last Modified: 18 Nov 2013

    LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability

    Source:Curesec Research Team
    Published:13 Jan 2020
    10
    Critical

    CVE-2013-6221

    Last Modified: 27 Jun 2014

    Directory traversal vulnerability in CommunicationServlet in HP Service Virtualization 3.x before 3.50.1, when the AutoPass license server is enabled, allows remote attackers to create arbitrary files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-2031.

    Source:Metasploit
    Published:18 Jun 2014
    10
    Critical

    CVE-2013-6194

    Last Modified: 24 Jan 2014

    Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1905.

    Source:Metasploit
    Published:4 Jan 2014
    6.8
    Medium

    CVE-2013-6167

    Last Modified: 24 Nov 2015

    Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.

    Source:anonymous
    Published:3 Apr 2013
    6.8
    Medium

    CVE-2013-6166

    Last Modified: 8 Oct 2015

    Google Chrome before 29 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.

    Source:anonymous
    Published:15 Feb 2014
    7.5
    High

    CVE-2013-6164

    Last Modified: 8 Nov 2013

    SQL injection vulnerability in view/objectDetail.php in Project'Or RIA 3.4.0 allows remote attackers to execute arbitrary SQL commands via the objectId parameter.

    Source:Vicente Aguilera Diaz
    Published:14 Nov 2013
    4.3
    Medium

    CVE-2013-6162

    Last Modified: 17 Dec 2013

    Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email.

    Source:David Um
    Published:21 Dec 2013
    7.5
    High

    CVE-2013-6129

    Last Modified: 23 Nov 2015

    The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] parameters, as exploited in the wild in October 2013.

    Source:Joshua Rogers
    Published:19 Oct 2013
    5.8
    Medium

    CVE-2013-6128

    Last Modified: 5 Sept 2013

    The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveToFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the single pathname argument, as demonstrated by a directory traversal attack.

    Source:blake
    Published:25 Oct 2013