9.3
    Critical

    CVE-2013-2642

    Last Modified: 8 Apr 2013

    Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation variable in a customized template, and remote authenticated users to execute arbitrary commands via shell metacharacters in the (2) url parameter to the Diagnostic Tools functionality or (3) entries parameter to the Local Site List functionality.

    Source:SEC Consult
    Published:18 Mar 2014
    5
    Medium

    CVE-2013-2641

    Last Modified: 8 Apr 2013

    Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.

    Source:SEC Consult
    Published:18 Mar 2014
    4.3
    Medium

    CVE-2013-2639

    Last Modified: 7 Feb 2014

    Cross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote attackers to inject arbitrary web script or HTML via the description in a project folder.

    Source:Luigi Vezzoso
    Published:11 Feb 2014
    6.1
    Medium

    CVE-2013-2637

    Last Modified: 8 Apr 2013

    A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via changes, workorder items, and FAQ articles, which could let a remote malicious user execute arbitrary code.

    Source:Luigi Vezzoso
    Published:12 Feb 2020
    7.5
    High

    CVE-2013-2627

    Last Modified: 8 Dec 2015

    SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to execute arbitrary SQL commands via the id parameter in a removeFolder action.

    Source:Alexandre Herzog
    Published:21 Dec 2013
    5.3
    Medium

    CVE-2013-2624

    Last Modified: 28 Oct 2015

    Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a specially crafted URL request.

    Source:Manuel García Cárdenas
    Published:3 Feb 2020
    6.1
    Medium

    CVE-2013-2623

    Last Modified: 27 Oct 2015

    Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.php.

    Source:Manuel García Cárdenas
    Published:3 Feb 2020
    6.1
    Medium

    CVE-2013-2621

    Last Modified: 28 Oct 2015

    Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.

    Source:Manuel García Cárdenas
    Published:3 Feb 2020
    5
    Medium

    CVE-2013-2619

    Last Modified: 2 Apr 2013

    Directory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a .. (dot dot) to the default URI.

    Source:Daniel Ricardo dos Santos
    Published:18 Mar 2014
    4.3
    Medium

    CVE-2013-2618

    Last Modified: 24 Oct 2016

    Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HTML via the map_title parameter.

    Source:Daniel Ricardo dos Santos
    Published:5 Jun 2014
    8.4
    High

    CVE-2013-2597

    Last Modified: 22 Apr 2026

    Stack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to gain privileges via an application that leverages /dev/msm_acdb access and provides a large size value in an ioctl argument.

    Published:31 Aug 2014
    7.8
    High

    CVE-2013-2596

    Last Modified: 21 Apr 2026

    Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted /dev/graphics/fb0 mmap2 system calls, as demonstrated by the Motochopper pwn program.

    Published:9 Apr 2013
    7.2
    High

    CVE-2013-2595

    Last Modified: 12 Apr 2025

    The device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, enables MSM_CAM_IOCTL_SET_MEM_MAP_INFO ioctl calls for an unrestricted mmap interface, which allows attackers to gain privileges via a crafted application.

    Published:31 Aug 2014
    7.5
    High

    CVE-2013-2594

    Last Modified: 25 Apr 2013

    SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref parameter.

    Source:Joseph Sheridan
    Published:21 Jan 2014
    4.3
    Medium

    CVE-2013-2586

    Last Modified: 30 Sept 2013

    XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method.

    Source:Manuel García Cárdenas
    Published:29 Sept 2014
    7.8
    High

    CVE-2013-2581

    Last Modified: 2 Aug 2013

    cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to modify the firmware revision via a "preset" action.

    Source:Core Security
    Published:11 Oct 2013
    7.1
    High

    CVE-2013-2580

    Last Modified: 2 Aug 2013

    Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, allows remote attackers to upload arbitrary files, then accessing it via a direct request to the file in the mnt/mtd directory.

    Source:Core Security
    Published:11 Oct 2013
    10
    Critical

    CVE-2013-2579

    Last Modified: 2 Aug 2013

    TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty password for the hardcoded "qmik" account, which allows remote attackers to obtain administrative access via a TELNET session.

    Source:Core Security
    Published:11 Oct 2013
    10
    Critical

    CVE-2013-2578

    Last Modified: 2 Aug 2013

    cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.

    Source:Core Security
    Published:11 Oct 2013
    9.3
    Critical

    CVE-2013-2577

    Last Modified: 23 Jul 2013

    Buffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.

    Source:Core Security
    Published:9 Aug 2013
    6.8
    Medium

    CVE-2013-2576

    Last Modified: 23 Jul 2013

    Buffer overflow in Artweaver before 3.1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted AWD file.

    Source:Core Security
    Published:9 Aug 2013
    7.5
    High

    CVE-2013-2574

    Last Modified: 24 Jul 2013

    An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could let a malicious user obtain sensitive information.

    Source:Core Security
    Published:29 Jan 2020
    9.8
    Critical

    CVE-2013-2573

    Last Modified: 29 May 2013

    A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.

    Source:Core Security
    Published:29 Jan 2020
    7.5
    High

    CVE-2013-2572

    Last Modified: 29 May 2013

    A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files.

    Source:Core Security
    Published:29 Jan 2020
    9.8
    Critical

    CVE-2013-2571

    Last Modified: 5 Jun 2013

    Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.

    Source:Core Security
    Published:28 Jan 2020
    9.8
    Critical

    CVE-2013-2570

    Last Modified: 29 May 2013

    A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8 function of the binary /opt/cgi/view/param, which could let a remove malicious user execute arbitrary code.

    Source:Core Security
    Published:29 Jan 2020
    7.5
    High

    CVE-2013-2569

    Last Modified: 29 May 2013

    A Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default, which could let a malicious user obtain unauthorized access to the live video stream.

    Source:Core Security
    Published:29 Jan 2020
    9.8
    Critical

    CVE-2013-2568

    Last Modified: 29 May 2013

    A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which could let a remote malicious user execute arbitrary code.

    Source:Core Security
    Published:29 Jan 2020
    7.5
    High

    CVE-2013-2567

    Last Modified: 29 May 2013

    An Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account found in boa.conf, which lets a remote malicious user obtain sensitive information.

    Source:Core Security
    Published:29 Jan 2020
    7.8
    High

    CVE-2013-2560

    Last Modified: 30 Sept 2015

    Directory traversal vulnerability in the web interface on Foscam devices with firmware before 11.37.2.49 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI, as demonstrated by discovering (1) web credentials or (2) Wi-Fi credentials.

    Source:Frederic Basse
    Published:15 Mar 2013
    6.5
    Medium

    CVE-2013-2559

    Last Modified: 8 Oct 2015

    SQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort parameter to system/authors/. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

    Source:High-Tech Bridge
    Published:27 Mar 2014
    8.8
    High

    CVE-2013-2551

    Last Modified: 13 Jun 2013

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.

    Source:Metasploit
    Published:11 Mar 2013
    4.3
    Medium

    CVE-2013-2504

    Last Modified: 18 Oct 2015

    Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:43zsec
    Published:29 Dec 2013
    5.8
    Medium

    CVE-2013-2503

    Last Modified: 1 Oct 2015

    Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code.

    Source:Chris John Riley
    Published:11 Mar 2013
    4.3
    Medium

    CVE-2013-2501

    Last Modified: 1 Oct 2015

    Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ProfileId field.

    Source:Aditya Balapure
    Published:22 Mar 2013
    7.5
    High

    CVE-2013-2498

    Last Modified: 19 Apr 2013

    SQL injection vulnerability in the login page in flexycms/modules/user/user_manager.php in SimpleHRM 2.3, 2.2, and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter to index.php/user/setLogin.

    Source:Doraemon
    Published:28 Feb 2014
    6.8
    Medium

    CVE-2013-2492

    Last Modified: 23 Mar 2017

    Stack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote attackers to execute arbitrary code via a crafted packet to TCP port 3050, related to a missing size check during extraction of a group number from CNCT information.

    Source:Metasploit
    Published:15 Mar 2013
    7.5
    High

    CVE-2013-2474

    Last Modified: 29 Mar 2013

    Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter.

    Source:High-Tech Bridge SA
    Published:27 Jan 2020
    10
    Critical

    CVE-2013-2472

    Last Modified: 17 Sept 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect ShortBandedRaster size checks" in 2D.

    Source:Packet Storm
    Published:18 Jun 2013
    10
    Critical

    CVE-2013-2470

    Last Modified: 3 Sept 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "ImagingLib byte lookup processing."

    Source:GuHe
    Published:18 Jun 2013
    9.8
    Critical

    CVE-2013-2465

    Last Modified: 19 Aug 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.

    Source:Metasploit
    Published:18 Jun 2013
    9.3
    Critical

    CVE-2013-2460

    Last Modified: 1 Jul 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Serviceability. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "insufficient access checks" in the tracing component.

    Source:Metasploit
    Published:18 Jun 2013
    3.7
    Low

    CVE-2013-2423

    Last Modified: 23 Apr 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from the original researcher that this vulnerability allows remote attackers to bypass permission checks by the MethodHandles method and modify arbitrary public final fields using reflection and type confusion, as demonstrated using integer and double fields to disable the security manager.

    Source:Metasploit
    Published:16 Apr 2013
    5
    Medium

    CVE-2013-2419

    Last Modified: 18 Apr 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect availability via unknown vectors related to 2D. NOTE: the previous information is from the April 2013 CPU. Oracle has not commented on claims from another vendor that this issue is related to "font processing errors" in the International Components for Unicode (ICU) Layout Engine before 51.2.

    Source:SEC Consult
    Published:16 Apr 2013
    4.3
    Medium

    CVE-2013-2416

    Last Modified: 18 Apr 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote attackers to affect integrity via unknown vectors related to Deployment.

    Source:SEC Consult
    Published:16 Apr 2013
    7.5
    High

    CVE-2013-2370

    Last Modified: 29 Aug 2013

    Unspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1671.

    Source:Metasploit
    Published:26 Jul 2013
    10
    Critical

    CVE-2013-2367

    Last Modified: 1 Apr 2017

    Multiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1678.

    Source:Metasploit
    Published:31 Jul 2013
    10
    Critical

    CVE-2013-2347

    Last Modified: 16 Feb 2014

    The Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary commands or cause a denial of service via a crafted EXEC_BAR packet to TCP port 5555, aka ZDI-CAN-1885.

    Source:Chris Graham
    Published:4 Jan 2014
    10
    Critical

    CVE-2013-2343

    Last Modified: 13 Aug 2013

    Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1510.

    Source:Metasploit
    Published:2 Jul 2013
    10
    Critical

    CVE-2013-2333

    Last Modified: 15 Oct 2013

    Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1680.

    Source:Metasploit
    Published:6 Jun 2013