9.3
    Critical

    CVE-2013-0726

    Last Modified: 14 May 2013

    Stack-based buffer overflow in the ERM_convert_to_correct_webpath function in ermapper_u.dll in ERDAS ER Viewer before 13.00.0001 allows remote attackers to execute arbitrary code via a crafted pathname in an ERS file.

    Source:Metasploit
    Published:5 May 2013
    4.4
    Medium

    CVE-2013-0722

    Last Modified: 7 Jan 2013

    Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow local users to gain privileges via a Trojan horse hosts list containing a long line.

    Source:Sajjad Pourali
    Published:11 Jan 2013
    7.1
    High

    CVE-2013-0699

    Last Modified: 27 Jul 2013

    The Galil RIO-47100 Pocket PLC allows remote attackers to cause a denial of service via a session that includes "repeated requests."

    Source:Sapling
    Published:1 May 2013
    6.8
    Medium

    CVE-2013-0663

    Last Modified: 15 Jun 2018

    Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests that execute commands, as demonstrated by modifying HTTP credentials.

    Source:t4rkd3vilz
    Published:4 Apr 2013
    9.3
    Critical

    CVE-2013-0662

    Last Modified: 20 Aug 2018

    Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.

    Source:Alejandro Parodi
    Published:28 Mar 2014
    10
    Critical

    CVE-2013-0658

    Last Modified: 10 Feb 2013

    Heap-based buffer overflow in RFManagerService.exe in Schneider Electric Accutech Manager 2.00.1 and earlier allows remote attackers to execute arbitrary code via a crafted HTTP request.

    Source:Evren Yalçın
    Published:15 Feb 2013
    10
    Critical

    CVE-2013-0657

    Last Modified: 31 May 2011

    Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol.

    Source:Metasploit
    Published:21 Jan 2013
    7.8
    High

    CVE-2013-0640

    Last Modified: 14 Jul 2017

    Adobe Reader and Acrobat 9.x before 9.5.4, 10.x before 10.1.6, and 11.x before 11.0.02 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted PDF document, as exploited in the wild in February 2013.

    Source:w3bd3vil & abh1sek
    Published:13 Feb 2013
    9.3
    Critical

    CVE-2013-0634

    Last Modified: 21 Apr 2014

    Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted SWF content, as exploited in the wild in February 2013.

    Source:Metasploit
    Published:7 Feb 2013
    9.3
    Critical

    CVE-2013-0633

    Last Modified: 21 Apr 2014

    Buffer overflow in Adobe Flash Player before 10.3.183.51 and 11.x before 11.5.502.149 on Windows and Mac OS X, before 10.3.183.51 and 11.x before 11.2.202.262 on Linux, before 11.1.111.32 on Android 2.x and 3.x, and before 11.1.115.37 on Android 4.x allows remote attackers to execute arbitrary code via crafted SWF content, as exploited in the wild in February 2013.

    Source:Metasploit
    Published:7 Feb 2013
    9.8
    Critical

    CVE-2013-0632

    Last Modified: 11 Dec 2013

    administrator.cfc in Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10 allows remote attackers to bypass authentication and possibly execute arbitrary code by logging in to the RDS component using the default empty password and leveraging this session to access the administrative web interface, as exploited in the wild in January 2013.

    Source:Metasploit
    Published:17 Jan 2013
    7.5
    High

    CVE-2013-0629

    Last Modified: 16 Nov 2017

    Adobe ColdFusion 9.0, 9.0.1, 9.0.2, and 10, when a password is not configured, allows attackers to access restricted directories via unspecified vectors, as exploited in the wild in January 2013.

    Source:Metasploit
    Published:9 Jan 2013
    9.8
    Critical

    CVE-2013-0625

    Last Modified: 16 Nov 2017

    Adobe ColdFusion 9.0, 9.0.1, and 9.0.2, when a password is not configured, allows remote attackers to bypass authentication and possibly execute arbitrary code via unspecified vectors, as exploited in the wild in January 2013.

    Source:Metasploit
    Published:9 Jan 2013
    8.5
    High

    CVE-2013-0526

    Last Modified: 19 Aug 2013

    ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.

    Source:Alejandro Alvarez Bravo
    Published:21 Aug 2013
    5.3
    Medium

    CVE-2013-0431

    Last Modified: 25 Feb 2013

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 through Update 11, and OpenJDK 7, allows user-assisted remote attackers to bypass the Java security sandbox via unspecified vectors related to JMX, aka "Issue 52," a different vulnerability than CVE-2013-1490.

    Source:Metasploit
    Published:27 Jan 2013
    9.8
    Critical

    CVE-2013-0422

    Last Modified: 11 Jan 2013

    Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using the public getMBeanInstantiator method in the JmxMBeanServer class to obtain a reference to a private MBeanInstantiator object, then retrieving arbitrary Class references using the findClass method, and (2) using the Reflection API with recursion in a way that bypasses a security check by the java.lang.invoke.MethodHandles.Lookup.checkSecurityManager method due to the inability of the sun.reflect.Reflection.getCallerClass method to skip frames related to the new reflection API, as exploited in the wild in January 2013, as demonstrated by Blackhole and Nuclear Pack, and a different vulnerability than CVE-2012-4681 and CVE-2012-3174. NOTE: some parties have mapped the recursive Reflection API issue to CVE-2012-3174, but CVE-2012-3174 is for a different vulnerability whose details are not public as of 20130114. CVE-2013-0422 covers both the JMX/MBean and Reflection API issues. NOTE: it was originally reported that Java 6 was also vulnerable, but the reporter has retracted this claim, stating that Java 6 is not exploitable because the relevant code is called in a way that does not bypass security checks. NOTE: as of 20130114, a reliable third party has claimed that the findClass/MBeanInstantiator vector was not fixed in Oracle Java 7 Update 11. If there is still a vulnerable condition, then a separate CVE identifier might be created for the unfixed issue.

    Source:Metasploit
    Published:10 Jan 2013
    6.4
    Medium

    CVE-2013-0397

    Last Modified: 16 Jan 2013

    Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Diagnostics.

    Source:Trustwave's SpiderLabs
    Published:17 Jan 2013
    7.5
    High

    CVE-2013-0333

    Last Modified: 29 Jan 2013

    lib/active_support/json/backends/yaml.rb in Ruby on Rails 2.3.x before 2.3.16 and 3.0.x before 3.0.20 does not properly convert JSON data to YAML data for processing by a YAML parser, which allows remote attackers to execute arbitrary code, conduct SQL injection attacks, or bypass authentication via crafted data that triggers unsafe decoding, a different vulnerability than CVE-2013-0156.

    Source:Metasploit
    Published:28 Jan 2013
    5
    Medium

    CVE-2013-0332

    Last Modified: 9 Dec 2013

    Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) view, (2) request, or (3) action parameter.

    Source:iye
    Published:20 Mar 2013
    6.5
    Medium

    CVE-2013-0303

    Last Modified: 12 Apr 2025

    Unspecified vulnerability in core/ajax/translations.php in ownCloud before 4.0.12 and 4.5.x before 4.5.6 allows remote authenticated users to execute arbitrary PHP code via unknown vectors. NOTE: this entry has been SPLIT due to different affected versions. The core/settings.php issue is covered by CVE-2013-7344.

    Published:23 Mar 2014
    7.2
    High

    CVE-2013-0292

    Last Modified: 2 Jun 2014

    The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.

    Source:Sebastian Krahmer
    Published:14 Feb 2013
    7.5
    High

    CVE-2013-0291

    Last Modified: 25 Sept 2015

    NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability

    Source:Henrique Montenegro
    Published:30 Jan 2020
    7.5
    High

    CVE-2013-0269

    Last Modified: 11 Apr 2025

    The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

    Published:11 Feb 2013
    6.2
    Medium

    CVE-2013-0268

    Last Modified: 2 Aug 2013

    The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c.

    Source:spender
    Published:24 Jan 2013
    7.5
    High

    CVE-2013-0249

    Last Modified: 11 Feb 2013

    Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the realm parameter in a (1) POP3, (2) SMTP or (3) IMAP message.

    Source:Volema
    Published:6 Feb 2013
    5
    Medium

    CVE-2013-0238

    Last Modified: 13 Apr 2013

    The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allows remote attackers to cause a denial of service (crash) via a mask that causes a negative number to be parsed.

    Source:kingcope
    Published:13 Feb 2013
    7.5
    High

    CVE-2013-0232

    Last Modified: 24 Jan 2013

    includes/functions.php in ZoneMinder Video Server 1.24.0, 1.25.0, and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) runState parameter in the packageControl function; or (2) key or (3) command parameter in the setDeviceStatusX10 function.

    Source:Metasploit
    Published:20 Mar 2013
    10
    Critical

    CVE-2013-0230

    Last Modified: 7 Jul 2015

    Stack-based buffer overflow in the ExecuteSoapAction function in the SOAPAction handler in the HTTP service in MiniUPnP MiniUPnPd 1.0 allows remote attackers to execute arbitrary code via a long quoted method.

    Source:Todor Donev
    Published:31 Jan 2013
    7.8
    High

    CVE-2013-0229

    Last Modified: 7 Jul 2015

    The ProcessSSDPRequest function in minissdp.c in the SSDP handler in MiniUPnP MiniUPnPd before 1.4 allows remote attackers to cause a denial of service (service crash) via a crafted request that triggers a buffer over-read.

    Source:Todor Donev
    Published:31 Jan 2013
    Unknown

    CVE-2013-225

    https://github.com/PentestinGxRoot/ShellEvil

    4.3
    Medium

    CVE-2013-0221

    Last Modified: 18 Sept 2015

    The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command, when using the (1) -d or (2) -M switch, which triggers a stack-based buffer overflow in the alloca function.

    Source:anonymous
    Published:15 Jan 2013
    4
    Medium

    CVE-2013-0212

    Last Modified: 11 Apr 2025

    store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows remote authenticated users to obtain sensitive information by reading the error messages.

    Published:29 Jan 2013
    7.5
    High

    CVE-2013-0209

    Last Modified: 24 Jan 2013

    lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.

    Source:Metasploit
    Published:23 Jan 2013
    4.9
    Medium

    CVE-2013-0192

    Last Modified: 18 Dec 2016

    File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.

    Source:SimpleAudit Team
    Published:7 Feb 2020
    3.5
    Low

    CVE-2013-0177

    Last Modified: 18 Sept 2015

    Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x allow remote authenticated users to inject arbitrary web script or HTML via the (1) Screenlet.title or (2) Image.alt Widget attribute, as demonstrated by the parentPortalPageId parameter to exampleext/control/ManagePortalPages.

    Source:Juan Caillava
    Published:30 Jan 2014
    2.6
    Low

    CVE-2013-0169

    Last Modified: 11 Apr 2025

    The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirement during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, aka the "Lucky Thirteen" issue.

    Published:4 Feb 2013
    5.4
    Medium

    CVE-2013-0161

    Last Modified: 13 Sept 2015

    Havalite CMS 1.1.7 has a stored XSS vulnerability

    Source:Henri Salo
    Published:29 Jan 2020
    2.1
    Low

    CVE-2013-0160

    Last Modified: 5 Feb 2013

    The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device.

    Source:vladz
    Published:7 Jan 2013
    7.5
    High

    CVE-2013-0156

    Last Modified: 12 Aug 2013

    active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.

    Source:Metasploit
    Published:8 Jan 2013
    5
    Medium

    CVE-2013-0145

    Last Modified: 15 May 2013

    Buffer overflow in the TFTPD service in Serva32 2.1.0 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long string in a read request.

    Source:Sapling
    Published:19 May 2013
    6.5
    Medium

    CVE-2013-0143

    Last Modified: 28 Oct 2015

    cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by leveraging guest access and placing shell metacharacters in the query string.

    Source:Tim Herres
    Published:7 Jun 2013
    7.9
    High

    CVE-2013-0140

    Last Modified: 17 Nov 2014

    SQL injection vulnerability in the Agent-Handler component in McAfee ePolicy Orchestrator (ePO) before 4.5.7 and 4.6.x before 4.6.6 allows remote attackers to execute arbitrary SQL commands via a crafted request over the Agent-Server communication channel.

    Source:st3n
    Published:1 May 2013
    8.5
    High

    CVE-2013-0136

    Last Modified: 17 May 2013

    Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbitrary files, or cause a denial of service (file deletion or renaming) via (1) the uploadPath parameter in an UPLOAD operation; the paths[] parameter in a (2) DELETE, (3) CUT, or (4) COPY operation; or the newPath parameter in a (5) CUT or (6) COPY operation.

    Source:Metasploit
    Published:1 Jun 2013
    7.5
    High

    CVE-2013-0135

    Last Modified: 9 Oct 2015

    Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via the id parameter to (1) addressbook/register/delete_user.php, (2) addressbook/register/edit_user.php, or (3) addressbook/register/edit_user_save.php; the email parameter to (4) addressbook/register/edit_user_save.php, (5) addressbook/register/reset_password.php, (6) addressbook/register/reset_password_save.php, or (7) addressbook/register/user_add_save.php; the username parameter to (8) addressbook/register/checklogin.php or (9) addressbook/register/reset_password_save.php; the (10) lastname, (11) firstname, (12) phone, (13) permissions, or (14) notes parameter to addressbook/register/edit_user_save.php; the (15) q parameter to addressbook/register/admin_index.php; the (16) site parameter to addressbook/register/linktick.php; the (17) password parameter to addressbook/register/reset_password.php; the (18) password_hint parameter to addressbook/register/reset_password_save.php; the (19) var parameter to addressbook/register/traffic.php; or a (20) BasicLogin cookie to addressbook/register/router.php.

    Source:Jurgen Voorneveld
    Published:9 Apr 2013
    6.8
    Medium

    CVE-2013-0126

    Last Modified: 19 Mar 2013

    Multiple cross-site request forgery (CSRF) vulnerabilities in index.cgi on the Verizon FIOS Actiontec MI424WR-GEN3I router with firmware 40.19.36 allow remote attackers to hijack the authentication of administrators for requests that (1) add administrative accounts via the username and user_level parameters or (2) enable remote administration via the is_telnet_primary and is_telnet_secondary parameters.

    Source:Jacob Holcomb
    Published:21 Mar 2013
    4.3
    Medium

    CVE-2013-0125

    Last Modified: 7 Oct 2015

    Cross-site scripting (XSS) vulnerability in fileview.asp in C2 WebResource allows remote attackers to inject arbitrary web script or HTML via the File parameter.

    Source:anonymous
    Published:4 Apr 2013
    7.2
    High

    CVE-2013-0109

    Last Modified: 17 Dec 2013

    The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not properly handle exceptions, which allows local users to gain privileges or cause a denial of service (memory overwrite) via a crafted application.

    Source:Metasploit
    Published:8 Apr 2013
    6.8
    Medium

    CVE-2013-0108

    Last Modified: 13 Mar 2013

    An ActiveX control in HscRemoteDeploy.dll in Honeywell Enterprise Buildings Integrator (EBI) R310, R400.2, R410.1, and R410.2; SymmetrE R310, R410.1, and R410.2; ComfortPoint Open Manager (aka CPO-M) Station R100; and HMIWeb Browser client packages allows remote attackers to execute arbitrary code via a crafted HTML document.

    Source:Metasploit
    Published:24 Feb 2013
    8.8
    High

    CVE-2013-0090

    Last Modified: 18 Dec 2016

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, aka "Internet Explorer CCaret Use After Free Vulnerability."

    Source:Skylined
    Published:13 Mar 2013
    7.8
    High

    CVE-2013-0074

    Last Modified: 23 Mar 2017

    Microsoft Silverlight 5, and 5 Developer Runtime, before 5.1.20125.0 does not properly validate pointers during HTML object rendering, which allows remote attackers to execute arbitrary code via a crafted Silverlight application, aka "Silverlight Double Dereference Vulnerability."

    Source:Metasploit
    Published:13 Mar 2013