6.5
    Medium

    CVE-2013-4490

    Last Modified: 19 Aug 2014

    The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

    Source:Metasploit
    Published:13 May 2014
    5
    Medium

    CVE-2013-4474

    Last Modified: 14 Dec 2016

    Format string vulnerability in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.3 allows remote attackers to cause a denial of service (crash) via format string specifiers in a destination filename.

    Source:Daniel Kahn Gillmor
    Published:26 Oct 2013
    6.5
    Medium

    CVE-2013-4468

    Last Modified: 8 Nov 2013

    VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php.

    Source:Metasploit
    Published:14 May 2014
    6.5
    Medium

    CVE-2013-4467

    Last Modified: 8 Nov 2013

    Multiple SQL injection vulnerabilities in the agent interface (agc/) in VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allow (1) remote attackers to execute arbitrary SQL commands via the campaign variable in SCRIPT_multirecording_AJAX.php, (2) remote authenticated users to execute arbitrary SQL commands via the server_ip parameter to manager_send.php, or (3) other unspecified vectors. NOTE: some of these details are obtained from third party information.

    Source:Metasploit
    Published:11 Mar 2014
    5
    Medium

    CVE-2013-4434

    Last Modified: 11 Apr 2025

    Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.

    Published:25 Oct 2013
    4.3
    Medium

    CVE-2013-4378

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in HtmlSessionInformationsReport.java in JavaMelody 1.46 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted X-Forwarded-For header.

    Published:30 Sept 2013
    7.2
    High

    CVE-2013-4362

    Last Modified: 16 Jan 2016

    WEB-DAV Linux File System (davfs2) 1.4.6 and 1.4.7 allow local users to gain privileges via unknown attack vectors in (1) kernel_interface.c and (2) mount_davfs.c, related to the "system" function.

    Source:Lorenzo Cantoni
    Published:30 Sept 2013
    7.1
    High

    CVE-2013-4348

    Last Modified: 11 Apr 2025

    The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.

    Published:31 Oct 2013
    4.3
    Medium

    CVE-2013-4341

    Last Modified: 13 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 allow remote attackers to inject arbitrary web script or HTML via a crafted blog link within an RSS feed.

    Source:Ciaran McNally
    Published:16 Sept 2013
    4.3
    Medium

    CVE-2013-4322

    Last Modified: 11 Apr 2025

    Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 processes chunked transfer coding without properly handling (1) a large total amount of chunked data or (2) whitespace characters in an HTTP header value within a trailer field, which allows remote attackers to cause a denial of service by streaming data. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-3544.

    Published:25 Feb 2014
    5
    Medium

    CVE-2013-4295

    Last Modified: 25 Nov 2015

    The gadget renderer in Apache Shindig 2.5.0 for PHP allows remote attackers to obtain sensitive information via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Source:Kousuke Ebihara
    Published:24 Oct 2013
    Low

    CVE-2013-4266

    Last Modified: 14 Jan 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5123. Reason: This candidate is a reservation duplicate of CVE-2013-5123. Notes: All CVE users should reference CVE-2013-5123 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:LiquidWorm
    Published:27 Aug 2013
    6.1
    Medium

    CVE-2013-4241

    Last Modified: 12 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) image, (3) url, or (4) testimonial parameter to the Testimonial form (hms-testimonials-addnew page); (5) date_format parameter to the Settings - Default form (hms-testimonials-settings page); (6) name parameter in a Save action to the Settings - Custom Fields form (hms-testimonials-settings-fields page); or (7) name parameter in a Save action to the Settings - Template form (hms-testimonials-templates-new page).

    Source:RogueCoder
    Published:30 Jan 2020
    6.8
    Medium

    CVE-2013-4240

    Last Modified: 12 Aug 2013

    Multiple cross-site request forgery (CSRF) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add new testimonials via the hms-testimonials-addnew page, (2) add new groups via the hms-testimonials-addnewgroup page, (3) change default settings via the hms-testimonials-settings page, (4) change advanced settings via the hms-testimonials-settings-advanced page, (5) change custom fields settings via the hms-testimonials-settings-fields page, or (6) change template settings via the hms-testimonials-templates-new page to wp-admin/admin.php.

    Source:RogueCoder
    Published:2 Apr 2014
    6.8
    Medium

    CVE-2013-4212

    Last Modified: 27 Nov 2013

    Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated by the pageTitle parameter in the !getPageTitle sub-URL to roller-ui/login.rol, which uses a subclass of UIAction, aka "OGNL Injection."

    Source:Metasploit
    Published:7 Dec 2013
    9.8
    Critical

    CVE-2013-4211

    Last Modified: 12 Aug 2013

    A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code

    Source:Metasploit
    Published:14 Feb 2020
    5.8
    Medium

    CVE-2013-4200

    Last Modified: 17 Nov 2015

    The isURLInPortal method in the URLTool class in in_portal.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 treats URLs starting with a space as a relative URL, which allows remote attackers to bypass the allow_external_login_sites filtering property, redirect users to arbitrary web sites, and conduct phishing attacks via a space before a URL in the "next" parameter to acl_users/credentials_cookie_auth/require_login.

    Source:Cyrill Bannwart
    Published:21 Jan 2014
    5.5
    Medium

    CVE-2013-4175

    Last Modified: 21 Nov 2024

    MySecureShell 1.31 has a Local Denial of Service Vulnerability

    Published:23 Jan 2020
    7.5
    High

    CVE-2013-4147

    Last Modified: 11 Nov 2015

    Multiple format string vulnerabilities in Yet Another Radius Daemon (YARD RADIUS) 1.1.2 allow context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in a request in the (1) log_msg function in log.c or (2) version or (3) build_version function in version.c.

    Source:Hamid Zamani
    Published:9 Aug 2013
    5
    Medium

    CVE-2013-4124

    Last Modified: 6 Sept 2017

    Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.

    Source:x90c
    Published:5 Aug 2013
    5
    Medium

    CVE-2013-4123

    Last Modified: 16 Jul 2013

    client_side_request.cc in Squid 3.2.x before 3.2.13 and 3.3.x before 3.3.8 allows remote attackers to cause a denial of service via a crafted port number in a HTTP Host header.

    Source:kingcope
    Published:13 Jul 2013
    4.3
    Medium

    CVE-2013-4117

    Last Modified: 5 Nov 2015

    Cross-site scripting (XSS) vulnerability in includes/CatGridPost.php in the Category Grid View Gallery plugin 2.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ID parameter.

    Source:Iranian Exploit DataBase
    Published:16 Jul 2013
    9.8
    Critical

    CVE-2013-4103

    Last Modified: 5 Nov 2015

    Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input

    Source:Mario Heiderich
    Published:4 Nov 2019
    5
    Medium

    CVE-2013-4098

    Last Modified: 5 Jun 2013

    ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter.

    Source:Pedro Andujar
    Published:28 Jun 2013
    5
    Medium

    CVE-2013-4097

    Last Modified: 5 Jun 2013

    ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in a -REG-E-OPEN error message.

    Source:Pedro Andujar
    Published:28 Jun 2013
    9
    Critical

    CVE-2013-4096

    Last Modified: 5 Jun 2013

    ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via shell metacharacters in the HOST_NAME field.

    Source:Pedro Andujar
    Published:28 Jun 2013
    6.5
    Medium

    CVE-2013-4095

    Last Modified: 5 Jun 2013

    plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to execute arbitrary commands via a task with a [command].value field in conjunction with an [arguments].value field.

    Source:Pedro Andujar
    Published:28 Jun 2013
    6.5
    Medium

    CVE-2013-4094

    Last Modified: 5 Jun 2013

    The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) private_key or (2) public_key parameter in a T/keyManagement request to plain/settings.html, as demonstrated by uploading a Linux ELF file and a shell script.

    Source:Pedro Andujar
    Published:28 Jun 2013
    5
    Medium

    CVE-2013-4093

    Last Modified: 5 Jun 2013

    The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information via (1) a direct request to dwr/call/plaincall/AsyncOperationsContainer.getOperationState.dwr, which reveals the installation path in the s0.filePath field, or (2) a T/keyManagement request to plain/settings.html, which reveals a temporary path in an error message.

    Source:Pedro Andujar
    Published:28 Jun 2013
    5
    Medium

    CVE-2013-4092

    Last Modified: 5 Jun 2013

    The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sensitive information by leveraging the presence of (1) a session ID in the jsessionid field to secsphLogin.jsp or (2) credentials in the j_password parameter to j_acegi_security_check, and reading (a) web-server access logs, (b) web-server Referer logs, or (c) the browser history.

    Source:Pedro Andujar
    Published:28 Jun 2013
    7.5
    High

    CVE-2013-4091

    Last Modified: 5 Jun 2013

    The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for the password (aka j_password) field on the secsphLogin.jsp login page, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

    Source:Pedro Andujar
    Published:28 Jun 2013
    5
    Medium

    CVE-2013-4074

    Last Modified: 28 May 2014

    The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

    Source:j0sm1
    Published:7 Jun 2013
    4
    Medium

    CVE-2013-4034

    Last Modified: 30 Nov 2015

    IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Source:IBM
    Published:16 Nov 2013
    6.9
    Medium

    CVE-2013-4015

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 6 through 10 allows local users to bypass the elevation policy check in the (1) Protected Mode or (2) Enhanced Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code.

    Source:Metasploit
    Published:26 Jul 2013
    7.2
    High

    CVE-2013-4011

    Last Modified: 30 Sept 2013

    Multiple unspecified vulnerabilities in the InfiniBand subsystem in IBM AIX 6.1 and 7.1, and VIOS 2.2.2.2-FP-26 SP-02, allow local users to gain privileges via vectors involving (1) arp.ib or (2) ibstat.

    Source:Kristian Erik Hermansen
    Published:18 Jul 2013
    7.1
    High

    CVE-2013-4002

    Last Modified: 11 Apr 2025

    XMLscanner.java in Apache Xerces2 Java Parser before 2.12.0, as used in the Java Runtime Environment (JRE) in IBM Java 5.0 before 5.0 SR16-FP3, 6 before 6 SR14, 6.0.1 before 6.0.1 SR6, and 7 before 7 SR5 as well as Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier, Java SE Embedded 7u40 and earlier, and possibly other products allows remote attackers to cause a denial of service via vectors related to XML attribute names.

    Published:23 Jul 2013
    6.5
    Medium

    CVE-2013-3969

    Last Modified: 10 Nov 2015

    The find prototype in scripting/engine_v8.h in MongoDB 2.4.0 through 2.4.4 allows remote authenticated users to cause a denial of service (uninitialized pointer dereference and server crash) or possibly execute arbitrary code via an invalid RefDB object.

    Source:SCRT Security
    Published:4 Jul 2013
    6.8
    Medium

    CVE-2013-3963

    Last Modified: 31 Oct 2015

    Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models allows remote attackers to hijack the authentication of unspecified victims for requests that add users.

    Source:Castillo
    Published:1 Oct 2013
    6.5
    Medium

    CVE-2013-3961

    Last Modified: 11 Jun 2013

    SQL injection vulnerability in edit_event.php in Simple PHP Agenda before 2.2.9 allows remote authenticated users to execute arbitrary SQL commands via the eventid parameter.

    Source:Anthony Dubuissez
    Published:11 Mar 2014
    7.2
    High

    CVE-2013-3956

    Last Modified: 13 Jul 2017

    The NICM.SYS kernel driver 3.1.11.0 in Novell Client 4.91 SP5 on Windows XP and Windows Server 2003; Novell Client 2 SP2 on Windows Vista and Windows Server 2008; and Novell Client 2 SP3 on Windows Server 2008 R2, Windows 7, Windows 8, and Windows Server 2012 allows local users to gain privileges via a crafted 0x143B6B IOCTL call.

    Source:sickness
    Published:31 Jul 2013
    9.3
    Critical

    CVE-2013-3934

    Last Modified: 2 Dec 2013

    Stack-based buffer overflow in Kingsoft Writer 2012 8.1.0.3030, as used in Kingsoft Office 2013 before 9.1.0.4256, allows remote attackers to execute arbitrary code via a long font name in a WPS file.

    Source:Julien Ahrens
    Published:10 Sept 2013
    9.3
    Critical

    CVE-2013-3928

    Last Modified: 15 Aug 2013

    Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote attackers to execute arbitrary code via crafted biPlanes and biBitCount fields in a BMP file.

    Source:Metasploit
    Published:11 Mar 2014
    8.8
    High

    CVE-2013-3918

    Last Modified: 27 Nov 2013

    The InformationCardSigninHelper Class ActiveX control in icardie.dll in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write) via a crafted web page that is accessed by Internet Explorer, as exploited in the wild in November 2013, aka "InformationCardSigninHelper Vulnerability."

    Source:Metasploit
    Published:12 Nov 2013
    7.8
    High

    CVE-2013-3906

    Last Modified: 3 Dec 2013

    GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and exploited in the wild in October and November 2013.

    Source:Metasploit
    Published:6 Nov 2013
    5.5
    Medium

    CVE-2013-3900

    Last Modified: 22 Apr 2026

    Why is Microsoft republishing a CVE from 2013? We are republishing CVE-2013-3900 in the Security Update Guide to update the Security Updates table and to inform customers that the EnableCertPaddingCheck is available in all currently supported versions of Windows 10 and Windows 11. While the format is different from the original CVE published in 2013, except for clarifications about how to configure the EnableCertPaddingCheck registry value, the information herein remains unchanged from the original text published on December 10, 2013, Microsoft does not plan to enforce the stricter verification behavior as a default functionality on supported releases of Microsoft Windows. This behavior remains available as an opt-in feature via reg key setting, and is available on supported editions of Windows released since December 10, 2013. This includes all currently supported versions of Windows 10 and Windows 11. The supporting code for this reg key was incorporated at the time of release for Windows 10 and Windows 11, so no security update is required; however, the reg key must be set. See the Security Updates table for the list of affected software. Vulnerability Description A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for portable executable (PE) files. An anonymous attacker could exploit the vulnerability by modifying an existing signed executable file to leverage unverified portions of the file in such a way as to add malicious code to the file without invalidating the signature. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Exploitation of this vulnerability requires that a user or application run or install a specially crafted, signed PE file. An attacker could modify an... See more at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2013-3900

    Published:11 Dec 2013
    8.8
    High

    CVE-2013-3897

    Last Modified: 15 Oct 2013

    Use-after-free vulnerability in the CDisplayPointer class in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JavaScript code that uses the onpropertychange event handler, as exploited in the wild in September and October 2013, aka "Internet Explorer Memory Corruption Vulnerability."

    Source:Metasploit
    Published:9 Oct 2013
    5.5
    Medium

    CVE-2013-3896

    Last Modified: 23 Mar 2017

    Microsoft Silverlight 5 before 5.1.20913.0 does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application, aka "Silverlight Vulnerability."

    Source:Metasploit
    Published:9 Oct 2013
    8.8
    High

    CVE-2013-3893

    Last Modified: 17 May 2021

    Use-after-free vulnerability in the SetMouseCapture implementation in mshtml.dll in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code via crafted JavaScript strings, as demonstrated by use of an ms-help: URL that triggers loading of hxds.dll.

    Source:SlidingWindow
    Published:18 Sept 2013
    7.2
    High

    CVE-2013-3881

    Last Modified: 11 Feb 2014

    win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1 and Windows Server 2008 R2 SP1 allows local users to gain privileges via a crafted application, aka "Win32k NULL Page Vulnerability."

    Source:Metasploit
    Published:9 Oct 2013
    9.3
    Critical

    CVE-2013-3846

    Last Modified: 10 Sept 2013

    Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted CSpliceTreeEngine::InsertSplice object in an HTML document, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3143 and CVE-2013-3161.

    Source:Metasploit
    Published:29 Dec 2013