Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 859 High, 2,914 Medium, 517 Low, 1 Unrated.

CVE-2013-5447

Published Dec 10, 2013

Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary code via an XFDL form with a long fontname v…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4408

Published Dec 10, 2013

Heap-based buffer overflow in the dcerpc_read_ncacn_packet_done function in librpc/rpc/dcerpc_util.c in winbindd in Samba 3.x before 3.6.22, 4.0.x before 4.0.13, and 4.1.x before…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort

CVE-2013-7027

Published Dec 9, 2013

The ieee80211_radiotap_iterator_init function in net/wireless/radiotap.c in the Linux kernel before 3.11.7 does not check whether a frame contains any data outside of the header,…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7026

Published Dec 9, 2013

Multiple race conditions in ipc/shm.c in the Linux kernel before 3.12.2 allow local users to cause a denial of service (use-after-free and system crash) or possibly have unspecifi…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6432

Published Dec 9, 2013

The ping_recvmsg function in net/ipv4/ping.c in the Linux kernel before 3.12.4 does not properly interact with read system calls on ping sockets, which allows local users to cause…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6431

Published Dec 9, 2013

The fib6_add function in net/ipv6/ip6_fib.c in the Linux kernel before 3.11.5 does not properly implement error-code encoding, which allows local users to cause a denial of servic…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6427

Published Dec 9, 2013

upgrade.py in the hp-upgrade service in HP Linux Imaging and Printing (HPLIP) 3.x through 3.13.11 launches a program from an http URL, which allows man-in-the-middle attackers to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4270

Published Dec 9, 2013

The net_ctl_permissions function in net/sysctl_net.c in the Linux kernel before 3.11.5 does not properly determine uid and gid values, which allows local users to bypass intended…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2930

Published Dec 9, 2013

The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Linux kernel before 3.12.2 does not properly restrict access to the perf subsystem, which allows local…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-2929

Published Dec 9, 2013

The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information fro…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6985

Published Dec 9, 2013

SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows remote attackers to execute arbitrary SQL commands via the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6039

Published Dec 9, 2013

Multiple cross-site scripting (XSS) vulnerabilities in NagiosQL 3.2 SP2 allow remote attackers to inject arbitrary web script or HTML via the txtSearch parameter to (1) admin/host…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5355

Published Dec 9, 2013

Multiple cross-site request forgery (CSRF) vulnerabilities in Sharetronix 3.1.1 allow remote attackers to hijack the authentication of administrators for requests that (1) change…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5354

Published Dec 9, 2013

Multiple SQL injection vulnerabilities in Sharetronix 3.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) fb_user_id or (2) tw_user_id parameter to signup.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-3929

Published Dec 9, 2013

Cross-site scripting (XSS) vulnerability in admin/editevent.php in CMS Made Simple (CMSMS) 1.11.9 allows remote authenticated users with the "Modify Events" permission to inject a…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-7024

Published Dec 9, 2013

The jpeg2000_decode_tile function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not consider the component number in certain calculations, which allows remote attackers to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7023

Published Dec 9, 2013

The ff_combine_frame function in libavcodec/parser.c in FFmpeg before 2.1 does not properly handle certain memory-allocation errors, which allows remote attackers to cause a denia…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7022

Published Dec 9, 2013

The g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 does not properly allocate memory for tiles, which allows remote attackers to cause a denial of service (…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7021

Published Dec 9, 2013

The filter_frame function in libavfilter/vf_fps.c in FFmpeg before 2.1 does not properly ensure the availability of FIFO content, which allows remote attackers to cause a denial o…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7020

Published Dec 9, 2013

The read_header function in libavcodec/ffv1dec.c in FFmpeg before 2.1 does not properly enforce certain bit-count and colorspace constraints, which allows remote attackers to caus…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7019

Published Dec 9, 2013

The get_cox function in libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not properly validate the reduction factor, which allows remote attackers to cause a denial of service (…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7018

Published Dec 9, 2013

libavcodec/jpeg2000dec.c in FFmpeg before 2.1 does not ensure the use of valid code-block dimension values, which allows remote attackers to cause a denial of service (out-of-boun…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-7017

Published Dec 9, 2013

libavcodec/jpeg2000.c in FFmpeg before 2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via crafted…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 326-350 of 5,187 CVEsPage 14 of 208