9.3
    Critical

    CVE-2013-3149

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 7 and 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3148

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3153.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3147

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 6 through 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3146

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3152.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3145

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3150.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3144

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3151 and CVE-2013-3163.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3143

    Last Modified: 16 Dec 2016

    Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3161.

    Source:Skylined
    Published:10 Jul 2013
    Low

    CVE-2013-3130

    Last Modified: 21 May 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3660, CVE-2013-3661. Reason: This candidate is a reservation duplicate of CVE-2013-3660 and CVE-2013-3661. Notes: All CVE users should reference CVE-2013-3660 and/or CVE-2013-3661 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Tavis Ormandy
    Published:30 May 2013
    9.3
    Critical

    CVE-2013-3120

    Last Modified: 1 Dec 2016

    Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3118 and CVE-2013-3125.

    Source:Skylined
    Published:12 Jun 2013
    9.3
    Critical

    CVE-2013-3115

    Last Modified: 10 Sept 2013

    Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3162.

    Source:Metasploit
    Published:10 Jul 2013
    9.3
    Critical

    CVE-2013-3111

    Last Modified: 13 Dec 2016

    Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2013-3123.

    Source:Skylined
    Published:12 Jun 2013
    6.8
    Medium

    CVE-2013-3098

    Last Modified: 28 Jul 2013

    Multiple cross-site request forgery (CSRF) vulnerabilities in TRENDnet TEW-812DRU router with firmware before 1.0.9.0 allow remote attackers to hijack the authentication of administrators for requests that (1) change admin credentials in a request to setSysAdm.cgi, (2) enable remote management or (3) enable port forwarding in an Apply action to uapply.cgi, or (4) have unspecified impact via a request to setNTP.cgi. NOTE: some of these details are obtained from third party information.

    Source:Jacob Holcomb
    Published:4 Feb 2014
    6.8
    Medium

    CVE-2013-3095

    Last Modified: 18 Oct 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to hijack the authentication of administrators for requests that (1) change the administrator password or (2) enable remote management via a request to hedwig.cgi or (3) activate configuration changes via a request to pigwidgeon.cgi.

    Source:Jacob Holcomb
    Published:19 Nov 2013
    6.8
    Medium

    CVE-2013-3083

    Last Modified: 19 Oct 2015

    Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attackers to hijack the authentication of administrators for requests that open the remote management interface on arbitrary ports via the remote_mgmt_enabled and remote_mgmt_port parameters.

    Source:Jacob Holcomb
    Published:29 Sept 2014
    4.3
    Medium

    CVE-2013-3082

    Last Modified: 23 Oct 2015

    Cross-site scripting (XSS) vulnerability in plugins/jojo_core/forgot_password.php in Jojo before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the search parameter to forgot-password/.

    Source:High-Tech Bridge SA
    Published:9 Jun 2014
    7.5
    High

    CVE-2013-3081

    Last Modified: 23 Oct 2015

    SQL injection vulnerability in the checkEmailFormat function in plugins/jojo_core/classes/Jojo.php in Jojo before 1.2.2 allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For HTTP header to /articles/test/.

    Source:High-Tech Bridge SA
    Published:9 Jun 2014
    10
    Critical

    CVE-2013-3075

    Last Modified: 22 Nov 2017

    Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities 7.10 and CitectScada 7.10r1, allow remote attackers to execute arbitrary code via a long string, as demonstrated by a long WzTitle property value to a certain ActiveX control.

    Source:Dr_IDE
    Published:19 Apr 2013
    7.5
    High

    CVE-2013-3050

    Last Modified: 9 Apr 2013

    SQL injection vulnerability in ZAPms 1.41 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter to product.

    Source:NoGe
    Published:12 Apr 2013
    6.8
    Medium

    CVE-2013-2977

    Last Modified: 11 Apr 2025

    Integer overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5.x before 8.5.3 FP5 and 9.x before 9.0.1 on Linux, allows remote attackers to execute arbitrary code via a malformed PNG image in a previewed e-mail message, aka SPR NPEI96K82Q.

    Published:10 May 2013
    6.5
    Medium

    CVE-2013-2945

    Last Modified: 8 May 2013

    SQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary SQL commands via the show_statuses[] parameter. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

    Source:High-Tech Bridge SA
    Published:2 Apr 2014
    6.9
    Medium

    CVE-2013-2852

    Last Modified: 29 Oct 2015

    Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including format string specifiers in an fwpostfix modprobe parameter, leading to improper construction of an error message.

    Source:Kees Cook
    Published:6 Jun 2013
    7.5
    High

    CVE-2013-2842

    Last Modified: 16 Aug 2016

    Use-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of widgets.

    Source:Google Security Research
    Published:22 May 2013
    7.5
    High

    CVE-2013-2827

    Last Modified: 11 Feb 2014

    An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code onto a client machine and execute this code via the ProjectURL property value.

    Source:Metasploit
    Published:15 Jan 2014
    9.3
    Critical

    CVE-2013-2817

    Last Modified: 15 Sept 2013

    An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute arbitrary programs via a crafted HTML document in conjunction with a Login Client button click.

    Source:blake
    Published:24 Feb 2014
    7.8
    High

    CVE-2013-2784

    Last Modified: 13 Jul 2013

    Triangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of data in Modbus/TCP packets, which allows remote attackers to cause a denial of service (networking outage) via a crafted packet to TCP port 502.

    Source:Sapling
    Published:10 Jul 2013
    5
    Medium

    CVE-2013-2765

    Last Modified: 31 May 2013

    The ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer dereference, process crash, and disk consumption) via a POST request with a large body and a crafted Content-Type header.

    Source:Younes JAAIDI
    Published:15 Jul 2013
    6.8
    Medium

    CVE-2013-2760

    Last Modified: 9 Apr 2013

    Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file.

    Source:Akshaysinh Vaghela
    Published:16 Apr 2013
    6.8
    Medium

    CVE-2013-2754

    Last Modified: 14 May 2013

    Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via a request to admin/users/add/user/do/.

    Source:High-Tech Bridge SA
    Published:11 Mar 2014
    10
    Critical

    CVE-2013-2751

    Last Modified: 25 Nov 2013

    Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to execute arbitrary Perl code via a crafted request, related to the "forgot password workflow."

    Source:Metasploit
    Published:12 Dec 2013
    4.3
    Medium

    CVE-2013-2750

    Last Modified: 7 Oct 2015

    Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:Simon Bieber
    Published:22 Jan 2014
    Low

    CVE-2013-2749

    Last Modified: 8 Nov 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-3528. Reason: This candidate is a reservation duplicate of CVE-2013-3528. Notes: All CVE users should reference CVE-2013-3528 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:EgiX
    Published:13 Oct 2013
    9.8
    Critical

    CVE-2013-2748

    Last Modified: 8 Apr 2013

    Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.

    Source:Daniel Buentello
    Published:28 Jan 2020
    9.8
    Critical

    CVE-2013-2739

    Last Modified: 10 Nov 2015

    MiniDLNA has heap-based buffer overflow

    Source:Zachary Cutlip
    Published:1 Nov 2019
    10
    Critical

    CVE-2013-2730

    Last Modified: 26 May 2013

    Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2733.

    Source:Metasploit
    Published:14 May 2013
    8.8
    High

    CVE-2013-2729

    Last Modified: 8 Jul 2013

    Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

    Source:feliam
    Published:14 May 2013
    6.1
    Medium

    CVE-2013-2714

    Last Modified: 1 Oct 2015

    Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.

    Source:hiphop
    Published:28 Jan 2020
    6.8
    Medium

    CVE-2013-2713

    Last Modified: 18 Apr 2013

    Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request.

    Source:High-Tech Bridge SA
    Published:23 May 2014
    4.3
    Medium

    CVE-2013-2712

    Last Modified: 18 Apr 2013

    Cross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via the content parameter.

    Source:High-Tech Bridge SA
    Published:23 May 2014
    7.5
    High

    CVE-2013-2690

    Last Modified: 29 Mar 2013

    SQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands via the loginid parameter in a logoff action.

    Source:Bhadresh Patel
    Published:28 Mar 2013
    6.1
    Medium

    CVE-2013-2684

    Last Modified: 27 Oct 2016

    Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:sqlhacker
    Published:6 Feb 2020
    5.3
    Medium

    CVE-2013-2683

    Last Modified: 27 Oct 2016

    Cisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private IP addresses and other sensitive information.

    Source:sqlhacker
    Published:6 Feb 2020
    4.3
    Medium

    CVE-2013-2682

    Last Modified: 27 Oct 2016

    Cisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive information.

    Source:sqlhacker
    Published:5 Feb 2020
    9.8
    Critical

    CVE-2013-2681

    Last Modified: 27 Oct 2016

    Cisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized access.

    Source:sqlhacker
    Published:5 Feb 2020
    7.5
    High

    CVE-2013-2680

    Last Modified: 27 Oct 2016

    Cisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.

    Source:sqlhacker
    Published:5 Feb 2020
    6.1
    Medium

    CVE-2013-2679

    Last Modified: 22 Jun 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7) submit_button parameter to storage/apply.cgi.

    Source:Carl Benedict
    Published:18 Feb 2020
    8.1
    High

    CVE-2013-2678

    Last Modified: 27 Oct 2016

    Cisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain sensitive information or execute arbitrary code by sending a crafted URL request to the apply.cgi script using the submit_type parameter.

    Source:sqlhacker
    Published:4 Feb 2020
    5.8
    Medium

    CVE-2013-2653

    Last Modified: 24 Sept 2018

    security/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to conduct phishing attacks without detection by the victim.

    Source:Fara Rustein
    Published:13 Nov 2013
    Unknown

    CVE-2013-2649

    https://www.exploit-db.com/exploits/38462

    9.3
    Critical

    CVE-2013-2645

    Last Modified: 19 Oct 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers to hijack the authentication of administrators for requests that (1) enable FTP access (aka "FTP directory traversal") to /tmp via the shareEntire parameter to userRpm/NasFtpCfgRpm.htm, (2) change the FTP administrative password via the nas_admin_pwd parameter to userRpm/NasUserAdvRpm.htm, (3) enable FTP on the WAN interface via the internetA parameter to userRpm/NasFtpCfgRpm.htm, (4) launch the FTP service via the startFtp parameter to userRpm/NasFtpCfgRpm.htm, or (5) enable or disable bandwidth limits via the QoSCtrl parameter to userRpm/QoSCfgRpm.htm.

    Source:Jacob Holcomb
    Published:6 Oct 2014
    4.3
    Medium

    CVE-2013-2643

    Last Modified: 8 Apr 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) xss parameter in an allow action to rss.php, (2) msg parameter to end-user/errdoc.php, (3) h parameter to end-user/ftp_redirect.php, or (4) threat parameter to the Blocked component.

    Source:SEC Consult
    Published:18 Mar 2014