6.5
    Medium

    CVE-2013-4882

    Last Modified: 13 Jul 2013

    Multiple SQL injection vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePolicy Orchestrator (ePO) extension for McAfee Agent (MA) 4.5 and 4.6, allow remote authenticated users to execute arbitrary SQL commands via the uid parameter to (1) core/showRegisteredTypeDetails.do and (2) EPOAGENTMETA/DisplayMSAPropsDetail.do, a different vulnerability than CVE-2013-0140.

    Source:Nuri Fattah
    Published:21 Jul 2013
    6.8
    Medium

    CVE-2013-4881

    Last Modified: 8 Aug 2013

    Cross-site request forgery (CSRF) vulnerability in core/admin/modules/users/create.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to hijack the authentication of administrators for requests that create an administrative user via an add user action to index.php.

    Source:High-Tech Bridge SA
    Published:19 Aug 2013
    4.3
    Medium

    CVE-2013-4880

    Last Modified: 8 Aug 2013

    Cross-site scripting (XSS) vulnerability in core/admin/modules/developer/modules/views/add.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to inject arbitrary web script or HTML via the module parameter.

    Source:High-Tech Bridge SA
    Published:13 Aug 2013
    7.5
    High

    CVE-2013-4879

    Last Modified: 8 Aug 2013

    SQL injection vulnerability in core/inc/bigtree/cms.php in BigTree CMS 4.0 RC2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to index.php.

    Source:High-Tech Bridge SA
    Published:13 Aug 2013
    7.5
    High

    CVE-2013-4878

    Last Modified: 22 Nov 2017

    The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote attackers to execute arbitrary code via a crafted request, a different vulnerability than CVE-2012-1823.

    Source:kingcope
    Published:18 Jul 2013
    5.3
    Medium

    CVE-2013-4868

    Last Modified: 2 Aug 2013

    Karotz API 12.07.19.00: Session Token Information Disclosure

    Source:Trustwave's SpiderLabs
    Published:27 Dec 2019
    6.3
    Medium

    CVE-2013-4867

    Last Modified: 2 Aug 2013

    Electronic Arts Karotz Smart Rabbit 12.07.19.00 allows Python module hijacking

    Source:Trustwave's SpiderLabs
    Published:27 Dec 2019
    6.5
    Medium

    CVE-2013-4865

    Last Modified: 2 Aug 2013

    Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to hijack the authentication of users for requests that install arbitrary firmware via the squashfs parameter.

    Source:Trustwave's SpiderLabs
    Published:28 Jan 2020
    9.8
    Critical

    CVE-2013-4864

    Last Modified: 2 Aug 2013

    MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.

    Source:Trustwave's SpiderLabs
    Published:28 Jan 2020
    8.8
    High

    CVE-2013-4863

    Last Modified: 27 Oct 2016

    The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute arbitrary Lua code via a RunLua action in a request to upnp/control/hag on port 49451 or (2) remote authenticated users to execute arbitrary Lua code via a RunLua action in a request to port_49451/upnp/control/hag.

    Source:Jacob Baines
    Published:28 Jan 2020
    8.1
    High

    CVE-2013-4862

    Last Modified: 2 Aug 2013

    MiCasaVerde VeraLite with firmware 1.5.408 does not properly restrict access, which allows remote authenticated users to (1) update the firmware via the squashfs parameter to upgrade_step2.sh or (2) obtain hashed passwords via the cgi-bin/cmh/backup.sh page.

    Source:Trustwave's SpiderLabs
    Published:28 Jan 2020
    6.5
    Medium

    CVE-2013-4861

    Last Modified: 2 Aug 2013

    Directory traversal vulnerability in cgi-bin/cmh/get_file.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows remote authenticated users to read arbirary files via a .. (dot dot) in the filename parameter.

    Source:Trustwave's SpiderLabs
    Published:28 Jan 2020
    8.1
    High

    CVE-2013-4859

    Last Modified: 2 Aug 2013

    INSTEON Hub 2242-222 lacks Web and API authentication

    Source:Trustwave's SpiderLabs
    Published:27 Dec 2019
    4.3
    Medium

    CVE-2013-4858

    Last Modified: 18 Jul 2013

    Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav.

    Source:ariarat
    Published:30 Dec 2013
    10
    Critical

    CVE-2013-4837

    Last Modified: 11 Dec 2013

    Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.

    Source:Metasploit
    Published:4 Nov 2013
    7.5
    High

    CVE-2013-4835

    Last Modified: 24 Dec 2013

    The APISiteScopeImpl SOAP service in HP SiteScope 10.1x and 11.x before 11.22 allows remote attackers to bypass authentication and execute arbitrary code via a direct request to the issueSiebelCmd method, aka ZDI-CAN-1765.

    Source:Metasploit
    Published:4 Nov 2013
    10
    Critical

    CVE-2013-4822

    Last Modified: 22 Oct 2013

    Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1606.

    Source:Metasploit
    Published:13 Oct 2013
    10
    Critical

    CVE-2013-4812

    Last Modified: 17 Sept 2013

    UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

    Source:Metasploit
    Published:13 Sept 2013
    10
    Critical

    CVE-2013-4811

    Last Modified: 17 Sept 2013

    UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.

    Source:Metasploit
    Published:13 Sept 2013
    9.8
    Critical

    CVE-2013-4810

    Last Modified: 2 Jan 2014

    HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, aka ZDI-CAN-1760. NOTE: this is probably a duplicate of CVE-2007-1036, CVE-2010-0738, and/or CVE-2012-0874.

    Source:rgod
    Published:11 Sept 2013
    9.3
    Critical

    CVE-2013-4800

    Last Modified: 1 Dec 2016

    Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1735.

    Source:Metasploit
    Published:26 Jul 2013
    10
    Critical

    CVE-2013-4798

    Last Modified: 4 Sept 2013

    Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1705.

    Source:Metasploit
    Published:26 Jul 2013
    7.5
    High

    CVE-2013-4789

    Last Modified: 2 Aug 2013

    SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via the "c" parameter to index.php.

    Source:High-Tech Bridge SA
    Published:9 Aug 2013
    5.1
    Medium

    CVE-2013-4788

    Last Modified: 30 Sept 2013

    The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address.

    Source:Hector Marco & Ismael Ripoll
    Published:15 Jul 2013
    9.3
    Critical

    CVE-2013-4787

    Last Modified: 16 Nov 2017

    Android 1.6 Donut through 4.2 Jelly Bean does not properly check cryptographic signatures for applications, which allows attackers to execute arbitrary code via an application package file (APK) that is modified in a way that does not violate the cryptographic signature, probably involving multiple entries in a Zip file with the same name in which one entry is validated but the other entry is installed, aka Android security bug 8219321 and the "Master Key" vulnerability.

    Source:Bluebox Security
    Published:9 Jul 2013
    7.5
    High

    CVE-2013-4786

    Last Modified: 5 Nov 2015

    The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC.

    Source:Dan Farmer
    Published:8 Jul 2013
    10
    Critical

    CVE-2013-4784

    Last Modified: 11 Apr 2025

    The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.

    Published:8 Jul 2013
    7.8
    High

    CVE-2013-4776

    Last Modified: 22 Aug 2013

    NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier, GS748Tv4 5.4.1.14, and GS510TP 5.0.4.4 allows remote attackers to cause a denial of service (reboot or crash) via a crafted HTTP request to filesystem/.

    Source:Juan J. Guelfo
    Published:19 Dec 2013
    7.8
    High

    CVE-2013-4775

    Last Modified: 22 Aug 2013

    NETGEAR ProSafe GS724Tv3 and GS716Tv2 with firmware 5.4.1.13 and earlier; GS748Tv4 with firmware 5.4.1.14; GS510TP with firmware 5.4.0.6; GS752TPS, GS728TPS, GS728TS, and GS725TS with firmware 5.3.0.17; and GS752TXS and GS728TXS with firmware 6.1.0.12 allows remote attackers to read encrypted administrator credentials and other startup configurations via a direct request to filesystem/startup-config.

    Source:Juan J. Guelfo
    Published:19 Dec 2013
    4.3
    Medium

    CVE-2013-4759

    Last Modified: 11 Nov 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the Magnolia Form module 1.x before 1.4.7 and 2.x before 2.0.2 for Magnolia CMS allow remote attackers to inject arbitrary web script or HTML via the (1) username, (2) fullname, or (3) email parameter to magnoliaPublic/demo-project/members-area/registration.html.

    Source:High-Tech Bridge
    Published:9 Aug 2013
    9.8
    Critical

    CVE-2013-4743

    Last Modified: 1 Jul 2013

    Static HTTP Server 1.0 has a Local Overflow

    Source:Jacob Holcomb
    Published:27 Dec 2019
    10
    Critical

    CVE-2013-4730

    Last Modified: 30 Jun 2013

    Buffer overflow in PCMan's FTP Server 2.0.7 allows remote attackers to execute arbitrary code via a long string in a USER command.

    Source:Chako
    Published:15 May 2014
    5
    Medium

    CVE-2013-4727

    Last Modified: 17 Nov 2015

    DDSN Interactive cm3 Acora CMS 6.0.6/1a, 6.0.2/1a, 5.5.7/12b, 5.5.0/1b-p1, and possibly other versions, allows remote attackers to obtain sensitive information via a request to Admin/top.aspx.

    Source:Pedro Andujar
    Published:6 Jun 2014
    9.3
    Critical

    CVE-2013-4710

    Last Modified: 23 Mar 2017

    Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly implement the WebView class, which allows remote attackers to execute arbitrary methods of Java objects or cause a denial of service (reboot) via a crafted web page, as demonstrated by use of the WebView.addJavascriptInterface method, a related issue to CVE-2012-6636.

    Source:Metasploit
    Published:3 Mar 2014
    7.8
    High

    CVE-2013-4695

    Last Modified: 2 Jul 2013

    Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution

    Source:Julien Ahrens
    Published:27 Dec 2019
    7.5
    High

    CVE-2013-4694

    Last Modified: 2 Jul 2013

    Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.

    Source:Julien Ahrens
    Published:16 Apr 2014
    6.1
    Medium

    CVE-2013-4692

    Last Modified: 26 Sept 2016

    Xorbin Analog Flash Clock 1.0 extension for Joomia has XSS

    Source:Prakhar Prasad
    Published:27 Dec 2019
    6.6
    Medium

    CVE-2013-4679

    Last Modified: 7 Mar 2019

    Symantec Workspace Virtualization before 6.x before 6.4.1953.0, when a virtual application layer is configured, allows local users to gain privileges via an application that performs crafted interaction with the operating system.

    Source:MJ0011
    Published:4 Aug 2013
    6.5
    Medium

    CVE-2013-4665

    Last Modified: 17 Jun 2013

    SPBAS Business Automation Software 2012 has CSRF.

    Source:Christy Philip Mathew
    Published:27 Dec 2019
    6.1
    Medium

    CVE-2013-4664

    Last Modified: 17 Jun 2013

    SPBAS Business Automation Software 2012 has XSS.

    Source:Christy Philip Mathew
    Published:27 Dec 2019
    6.8
    Medium

    CVE-2013-4660

    Last Modified: 30 Sept 2013

    The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation.

    Source:Metasploit
    Published:28 Jun 2013
    9.8
    Critical

    CVE-2013-4659

    Last Modified: 4 Dec 2016

    Buffer overflow in Broadcom ACSD allows remote attackers to execute arbitrary code via a long string to TCP port 5916. This component is used on routers of multiple vendors including ASUS RT-AC66U and TRENDnet TEW-812DRU.

    Source:Jacob Holcomb
    Published:14 Mar 2017
    7.8
    High

    CVE-2013-4631

    Last Modified: 8 Jan 2018

    Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 is enabled, allow remote attackers to cause a denial of service (device crash) via malformed SNMPv3 requests that leverage unspecified overflow issues.

    Source:Roberto Paleari
    Published:20 Jun 2013
    7.6
    High

    CVE-2013-4630

    Last Modified: 8 Jan 2018

    Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers to execute arbitrary code via malformed SNMPv3 requests.

    Source:Roberto Paleari
    Published:20 Jun 2013
    4.3
    Medium

    CVE-2013-4625

    Last Modified: 11 Nov 2015

    Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter.

    Source:High-Tech Bridge
    Published:9 Aug 2013
    4.3
    Medium

    CVE-2013-4624

    Last Modified: 11 Nov 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web script or HTML via (1) the site parameter to engines/manager.jsp, (2) the searchString parameter to administration/ in a search action, or the (3) username, (4) firstName, (5) lastName, (6) email, or (7) organization field to administration/ in a users action.

    Source:High-Tech Bridge
    Published:27 Nov 2013
    4.3
    Medium

    CVE-2013-4620

    Last Modified: 9 Nov 2015

    Cross-site scripting (XSS) vulnerability in interface/main/onotes/office_comments_full.php in OpenEMR 4.1.1 allows remote attackers to inject arbitrary web script or HTML via the note parameter.

    Source:Nate Drier
    Published:9 Aug 2013
    4.3
    Medium

    CVE-2013-4579

    Last Modified: 30 Nov 2015

    The ath9k_htc_set_bssid_mask function in drivers/net/wireless/ath/ath9k/htc_drv_main.c in the Linux kernel through 3.12 uses a BSSID masking approach to determine the set of MAC addresses on which a Wi-Fi device is listening, which allows remote attackers to discover the original MAC address after spoofing by sending a series of packets to MAC addresses with certain bit manipulations.

    Source:Mathy Vanhoef
    Published:14 Nov 2013
    7.5
    High

    CVE-2013-4547

    Last Modified: 2 Dec 2015

    nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.

    Source:Ivan Fratric
    Published:23 Nov 2013
    4.3
    Medium

    CVE-2013-4517

    Last Modified: 11 Apr 2025

    Apache Santuario XML Security for Java before 1.5.6, when applying Transforms, allows remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.

    Published:1 Nov 2013