5
    Medium

    CVE-2013-1861

    Last Modified: 3 Oct 2015

    MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.

    Source:Alyssa Milburn
    Published:5 Mar 2013
    7.5
    High

    CVE-2013-1852

    Last Modified: 15 Mar 2013

    SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the league_id parameter in the leaguemanager-export page to wp-admin/admin.php.

    Source:Joshua Reynolds
    Published:5 Feb 2014
    5
    Medium

    CVE-2013-1847

    Last Modified: 8 Oct 2015

    The mod_dav_svn Apache HTTPD server module in Subversion 1.6.0 through 1.6.20 and 1.7.0 through 1.7.8 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via an anonymous LOCK for a URL that does not exist.

    Source:anonymous
    Published:4 Apr 2013
    6.9
    Medium

    CVE-2013-1828

    Last Modified: 4 Sept 2016

    The sctp_getsockopt_assoc_stats function in net/sctp/socket.c in the Linux kernel before 3.8.4 does not validate a size value before proceeding to a copy_from_user operation, which allows local users to gain privileges via a crafted application that contains an SCTP_GET_ASSOC_STATS getsockopt system call.

    Source:Petr Matousek
    Published:8 Mar 2013
    4
    Medium

    CVE-2013-1814

    Last Modified: 13 Mar 2013

    The users/get program in the User RPC API in Apache Rave 0.11 through 0.20 allows remote authenticated users to obtain sensitive information about all user accounts via the offset parameter, as demonstrated by discovering password hashes in the password field of a response.

    Source:Andreas Guth
    Published:14 Mar 2013
    5
    Medium

    CVE-2013-1807

    Last Modified: 1 Mar 2013

    PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information via a direct request to the backup file in administration/db_backups/.

    Source:waraxe
    Published:30 Apr 2014
    6.5
    Medium

    CVE-2013-1806

    Last Modified: 1 Mar 2013

    Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to maincore.php; or remote authenticated administrators to delete arbitrary files via the (2) enable parameter to administration/user_fields.php or (3) file parameter to administration/db_backup.php.

    Source:waraxe
    Published:30 Apr 2014
    Low

    CVE-2013-1805

    Last Modified: 1 Mar 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-1806. Reason: This issue was MERGED into CVE-2013-1806 in accordance with CVE content decisions, because it is the same type of vulnerability and affects the same versions. Notes: All CVE users should reference CVE-2013-1806 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:waraxe
    Published:30 Apr 2014
    4.3
    Medium

    CVE-2013-1804

    Last Modified: 1 Mar 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php; or remote authenticated users with certain permissions to inject arbitrary web script or HTML via the (2) user_list or (3) user_types parameter to messages.php; (4) message parameter to infusions/shoutbox_panel/shoutbox_admin.php; (5) message parameter to administration/news.php; (6) panel_list parameter to administration/panel_editor.php; (7) HTTP User Agent string to administration/phpinfo.php; (8) "__BBCODE__" parameter to administration/bbcodes.php; errorMessage parameter to (9) article_cats.php, (10) download_cats.php, (11) news_cats.php, or (12) weblink_cats.php in administration/, when error is 3; or (13) body or (14) body2 parameter to administration/articles.php.

    Source:waraxe
    Published:29 Apr 2014
    7.5
    High

    CVE-2013-1803

    Last Modified: 1 Mar 2013

    Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby parameter to downloads.php; or remote authenticated users with certain permissions to execute arbitrary SQL commands via a (2) parameter name starting with "delete_attach_" in an edit action to forum/postedit.php; the (3) poll_opts[] parameter in a newthread action to forum/postnewthread.php; the (4) pm_email_notify, (5) pm_save_sent, (6) pm_inbox, (7) pm_sentbox, or (8) pm_savebox parameter to administration/settings_messages.php; the (9) thumb_compression, (10) photo_watermark_text_color1, (11) photo_watermark_text_color2, or (12) photo_watermark_text_color3 parameter to administration/settings_photo.php; the (13) enable parameter to administration/bbcodes.php; the (14) news_image, (15) news_image_t1, or (16) news_image_t2 parameter to administration/news.php; the (17) news_id parameter in an edit action to administration/news.php; or the (18) article_id parameter in an edit action to administration/articles.php. NOTE: the user ID cookie issue in Authenticate.class.php is already covered by CVE-2013-7375.

    Source:waraxe
    Published:5 May 2014
    6.9
    Medium

    CVE-2013-1775

    Last Modified: 29 Aug 2013

    sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.

    Source:Metasploit
    Published:27 Feb 2013
    6.2
    Medium

    CVE-2013-1773

    Last Modified: 21 Dec 2016

    Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileges or cause a denial of service (system crash) via a VFAT write operation on a filesystem with the utf8 mount option, which is not properly handled during UTF-8 to UTF-16 conversion.

    Source:G13
    Published:9 Dec 2012
    4.3
    Medium

    CVE-2013-1765

    Last Modified: 28 Sept 2015

    Multiple cross-site scripting (XSS) vulnerabilities in jwplayer.swf in the smart-flv plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) link or (2) playerready parameter.

    Source:Henri Salo
    Published:14 May 2014
    7.2
    High

    CVE-2013-1763

    Last Modified: 24 Apr 2015

    Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows local users to gain privileges via a large family value in a Netlink message.

    Source:SynQ
    Published:24 Feb 2013
    7.5
    High

    CVE-2013-1748

    Last Modified: 7 Dec 2016

    Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) edit.php or (2) import.php. NOTE: the view.php id vector is already covered by CVE-2008-2565.1 and the edit.php id vector is already covered by CVE-2008-2565.2.

    Source:CWH Underground
    Published:18 Apr 2013
    9.8
    Critical

    CVE-2013-1744

    Last Modified: 17 Dec 2012

    IRIS citations management tool through 1.3 allows remote attackers to execute arbitrary commands.

    Source:aeon
    Published:25 Jan 2020
    4.3
    Medium

    CVE-2013-1743

    Last Modified: 25 Nov 2015

    Multiple cross-site scripting (XSS) vulnerabilities in report.cgi in Bugzilla 4.1.x and 4.2.x before 4.2.7 and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via a field value that is not properly handled during construction of a tabular report, as demonstrated by the (1) summary or (2) real name field. NOTE: this issue exists because of an incomplete fix for CVE-2012-4189.

    Source:Mateusz Goik
    Published:24 Oct 2013
    4.3
    Medium

    CVE-2013-1742

    Last Modified: 25 Nov 2015

    Multiple cross-site scripting (XSS) vulnerabilities in editflagtypes.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id or (2) sortkey parameter.

    Source:Mateusz Goik
    Published:24 Oct 2013
    4
    Medium

    CVE-2013-1727

    Last Modified: 20 Nov 2015

    Mozilla Firefox before 24.0 on Android allows attackers to bypass the Same Origin Policy, and consequently conduct cross-site scripting (XSS) attacks or obtain password or cookie information, by using a symlink in conjunction with a file: URL for a local file.

    Source:Takeshi Terada
    Published:18 Sept 2013
    10
    Critical

    CVE-2013-1710

    Last Modified: 1 Apr 2017

    The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code or conduct cross-site scripting (XSS) attacks via vectors related to Certificate Request Message Format (CRMF) request generation.

    Source:Metasploit
    Published:7 Aug 2013
    8.8
    High

    CVE-2013-1690

    Last Modified: 8 Aug 2013

    Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

    Source:Metasploit
    Published:25 Jun 2013
    4.3
    Medium

    CVE-2013-1670

    Last Modified: 19 Aug 2014

    The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct cross-site scripting (XSS) attacks via a crafted web site.

    Source:Metasploit
    Published:14 May 2013
    8.5
    High

    CVE-2013-1668

    Last Modified: 7 Mar 2013

    The uploadFile function in upload/index.php in CosCMS before 1.822 allows remote administrators to execute arbitrary commands via shell metacharacters in the name of an uploaded file.

    Source:High-Tech Bridge SA
    Published:23 May 2014
    6.9
    Medium

    CVE-2013-1662

    Last Modified: 18 Nov 2016

    vmware-mount in VMware Workstation 8.x and 9.x and VMware Player 4.x and 5.x, on systems based on Debian GNU/Linux, allows host OS users to gain host OS privileges via a crafted lsb_release binary in a directory in the PATH, related to use of the popen library function.

    Source:Tavis Ormandy
    Published:24 Aug 2013
    5.8
    Medium

    CVE-2013-1651

    Last Modified: 15 Mar 2013

    OXUpdater in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof update servers and install arbitrary software via a crafted certificate.

    Source:Martin Braun
    Published:5 Sept 2013
    2.1
    Low

    CVE-2013-1650

    Last Modified: 15 Mar 2013

    Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses weak permissions (group "other" readable) under opt/open-xchange/etc/, which allows local users to obtain sensitive information via standard filesystem operations.

    Source:Martin Braun
    Published:5 Sept 2013
    4.3
    Medium

    CVE-2013-1649

    Last Modified: 15 Mar 2013

    Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 uses the crypt and SHA-1 algorithms for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.

    Source:Martin Braun
    Published:5 Sept 2013
    3.5
    Low

    CVE-2013-1648

    Last Modified: 15 Mar 2013

    The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue.

    Source:Martin Braun
    Published:5 Sept 2013
    5
    Medium

    CVE-2013-1647

    Last Modified: 15 Mar 2013

    Multiple CRLF injection vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter, as demonstrated by (1) the location parameter to ajax/redirect or (2) multiple infostore URIs.

    Source:Martin Braun
    Published:5 Sept 2013
    4.3
    Medium

    CVE-2013-1646

    Last Modified: 15 Mar 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allow remote attackers to inject arbitrary web script or HTML via (1) invalid JSON data in a mail-sending POST request, (2) an arbitrary parameter to servlet/TestServlet, (3) a javascript: URL in a standalone-mode action to a UWA module, (4) an infostore attachment, (5) JavaScript code in a contact image, (6) an RSS feed, or (7) a signature.

    Source:Martin Braun
    Published:5 Sept 2013
    4
    Medium

    CVE-2013-1645

    Last Modified: 15 Mar 2013

    Directory traversal vulnerability in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the publication template path.

    Source:Martin Braun
    Published:5 Sept 2013
    9.3
    Critical

    CVE-2013-1638

    Last Modified: 5 Feb 2013

    Opera before 12.13 allows remote attackers to execute arbitrary code via crafted clipPaths in an SVG document.

    Source:Cons0ul
    Published:8 Feb 2013
    4.3
    Medium

    CVE-2013-1636

    Last Modified: 28 Sept 2015

    Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in the Pretty Link Lite plugin before 1.6.3 for WordPress, JNews (com_jnews) component 8.0.1 for Joomla!, and CiviCRM 3.1.0 through 4.2.9 and 4.3.0 through 4.3.3, allows remote attackers to inject arbitrary web script or HTML via the get-data parameter.

    Source:hiphop
    Published:12 Mar 2014
    7.8
    High

    CVE-2013-1627

    Last Modified: 8 Dec 2012

    Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in an argument to the sub_401A90 CreateFileW function.

    Source:Nin3
    Published:11 Mar 2013
    8.3
    High

    CVE-2013-1616

    Last Modified: 27 Jul 2013

    The management console on the Symantec Web Gateway (SWG) appliance before 5.1.1 allows remote attackers to execute arbitrary commands by injecting a command into an application script.

    Source:SEC Consult
    Published:31 Jul 2013
    7.9
    High

    CVE-2013-1612

    Last Modified: 14 Jul 2017

    Buffer overflow in secars.dll in the management console in Symantec Endpoint Protection Manager (SEPM) 12.1.x before 12.1.3, and Symantec Endpoint Protection Center (SPC) Small Business Edition 12.0.x, allows remote attackers to execute arbitrary code via unspecified vectors.

    Source:st3n
    Published:20 Jun 2013
    7.5
    High

    CVE-2013-1606

    Last Modified: 12 Jun 2013

    Buffer overflow in the ubnt-streamer RTSP service on the Ubiquiti UBNT AirCam with airVision firmware before 1.1.6 allows remote attackers to execute arbitrary code via a long rtsp: URI in a DESCRIBE request.

    Source:Core Security
    Published:18 Jul 2013
    7.5
    High

    CVE-2013-1605

    Last Modified: 29 May 2013

    Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in a GET request.

    Source:Core Security
    Published:25 Mar 2014
    5
    Medium

    CVE-2013-1604

    Last Modified: 29 May 2013

    Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.

    Source:Core Security
    Published:25 Mar 2014
    5.3
    Medium

    CVE-2013-1603

    Last Modified: 1 May 2013

    An Authentication vulnerability exists in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03 due to hard-coded credentials that serve as a backdoor, which allows remote attackers to access the RTSP video stream.

    Source:Core Security
    Published:28 Jan 2020
    7.5
    High

    CVE-2013-1602

    Last Modified: 1 May 2013

    An Information Disclosure vulnerability exists due to insufficient validation of authentication cookies for the RTSP session in D-Link DCS-5635 1.01, DCS-1100L 1.04, DCS-1130L 1.04, DCS-1100 1.03/1.04_US, DCS-1130 1.03/1.04_US , DCS-2102 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-2121 1.05_RU/1.06/1.06_FR/1.05_TESCO, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.0, DCS-7410 1.0, DCS-7510 1.0, and WCS-1100 1.02, which could let a malicious user obtain unauthorized access to video streams.

    Source:Core Security
    Published:28 Jan 2020
    5.3
    Medium

    CVE-2013-1601

    Last Modified: 1 May 2013

    An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK An Information Disclosure vulnerability exists due to a failure to restrict access on the lums.cgi script when processing a live video stream in D-LINK WCS-1100 1.02, TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-7510 1.00, DCS-7410 1.00, DCS-6410 1.00, DCS-5635 1.01, DCS-5605 1.01, DCS-5230L 1.02, DCS-5230 1.02, DCS-3430 1.02, DCS-3411 1.02, DCS-3410 1.02, DCS-2121 1.06_FR, DCS-2121 1.06, DCS-2121 1.05_RU, DCS-2102 1.06_FR, DCS-2102 1.06, DCS-2102 1.05_RU, DCS-1130L 1.04, DCS-1130 1.04_US, DCS-1130 1.03, DCS-1100L 1.04, DCS-1100 1.04_US, and DCS-1100 1.03, which could let a malicious user obtain sensitive information. which could let a malicious user obtain sensitive information.

    Source:Core Security
    Published:28 Jan 2020
    5.3
    Medium

    CVE-2013-1600

    Last Modified: 1 May 2013

    An Authentication Bypass vulnerability exists in upnp/asf-mp4.asf when streaming live video in D-Link TESCO DCS-2121 1.05_TESCO, TESCO DCS-2102 1.05_TESCO, DCS-2121 1.06_FR, 1.06, and 1.05_RU, DCS-2102 1.06_FR. 1.06, and 1.05_RU, which could let a malicious user obtain sensitive information.

    Source:Core Security
    Published:28 Jan 2020
    9.8
    Critical

    CVE-2013-1599

    Last Modified: 1 May 2013

    A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firmware 1.02, DCS-5605/5635 1.01, DCS-1100L/1130L 1.04, DCS-1100/1130 1.03, DCS-1100/1130 1.04_US, DCS-2102/2121 1.05_RU, DCS-3410 1.02, DCS-5230 1.02, DCS-5230L 1.02, DCS-6410 1.00, DCS-7410 1.00, DCS-7510 1.00, and WCS-1100 1.02, which could let a remote malicious user execute arbitrary commands through the camera’s web interface.

    Source:Core Security
    Published:28 Jan 2020
    8.8
    High

    CVE-2013-1598

    Last Modified: 1 May 2013

    A Command Injection vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via the system.ntp parameter to the farseer.out binary file, which cold let a malicious user execute arbitrary code.

    Source:Core Security
    Published:24 Jan 2020
    6.5
    Medium

    CVE-2013-1597

    Last Modified: 1 May 2013

    A Directory Traversal vulnerability exists in Vivotek PT7135 IP Cameras 0300a and 0400a via a specially crafted GET request, which could let a malicious user obtain user credentials.

    Source:Core Security
    Published:24 Jan 2020
    5.3
    Medium

    CVE-2013-1596

    Last Modified: 1 May 2013

    An Authentication Bypass Vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via specially crafted RTSP packets to TCP port 554.

    Source:Core Security
    Published:24 Jan 2020
    9.8
    Critical

    CVE-2013-1595

    Last Modified: 1 May 2013

    A Buffer Overflow vulnerability exists in Vivotek PT7135 IP Camera 0300a and 0400a via a specially crafted packet in the Authorization header field sent to the RTSP service, which could let a remote malicious user execute arbitrary code or cause a Denial of Service.

    Source:Core Security
    Published:24 Jan 2020
    7.5
    High

    CVE-2013-1594

    Last Modified: 1 May 2013

    An Information Disclosure vulnerability exists via a GET request in Vivotek PT7135 IP Camera 0300a and 0400a due to wireless keys and 3rd party credentials stored in clear text.

    Source:Core Security
    Published:24 Jan 2020
    9.8
    Critical

    CVE-2013-1592

    Last Modified: 17 Feb 2013

    A Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Server packets to remote TCP ports 36NN and/or 39NN in SAP NetWeaver 2004s, 7.01 SR1, 7.02 SP06, and 7.30 SP04, which could let a remote malicious user execute arbitrary code.

    Source:Core Security
    Published:23 Jan 2020