Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 859 High, 2,914 Medium, 517 Low, 1 Unrated.

CVE-2013-6901

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0, when Firefox is used, allows remote attackers to inject arbitrary web script or HTML…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6900

Published Dec 5, 2013

Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via un…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6004

Published Dec 5, 2013

Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6003

Published Dec 5, 2013

CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6002

Published Dec 5, 2013

The server in Cybozu Garoon before 3.7 SP1 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6001

Published Dec 5, 2013

SQL injection vulnerability in the Space function in Cybozu Garoon before 3.7 SP1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6000

Published Dec 5, 2013

Directory traversal vulnerability in Tattyan HP TOWN before 5_10_1 allows remote attackers to read arbitrary files via a .. (dot dot) in a request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6945

Published Dec 4, 2013

The M2M Broker in OSEHRA VistA, as distributed before September 30, 2013, allows attackers to bypass authentication and authorization to perform doctor-only actions and read or mo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6936

Published Dec 4, 2013

Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL comm…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6935

Published Dec 4, 2013

Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the SourcePath value in a .wcf file.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-6702

Published Dec 4, 2013

The management implementation on Cisco ONS 15454 controller cards with software 9.8 and earlier allows remote attackers to cause a denial of service (card reset) via crafted packe…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6029

Published Dec 4, 2013

Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code via a malformed .SVT file.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5449

Published Dec 4, 2013

Cross-site scripting (XSS) vulnerability in workingSet.jsp in IBM Eclipse Help System (IEHS), as used in the installable InfoCenter component in IBM FileNet Content Manager 4.5.1,…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6937

Published Dec 4, 2013

Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the name attribute of the cols element in a…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6705

Published Dec 3, 2013

The IP Device Tracking (IPDT) feature in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (IPDT AVL corruption and device reload) via a crafted sequence o…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6704

Published Dec 3, 2013

Cisco IOS XE does not properly manage memory for TFTP UDP flows, which allows remote attackers to cause a denial of service (memory consumption) via TFTP (1) client or (2) server…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6703

Published Dec 3, 2013

The TLS/SSLv3 module on Cisco ONS 15454 controller cards allows remote attackers to cause a denial of service (card reset) via crafted (1) TLS or (2) SSLv3 packets, aka Bug ID CSC…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6690

Published Dec 3, 2013

Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Assurance component in Cisco Prime Collaboration allow remote attackers to inject arbitrary web scr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6150

Published Dec 3, 2013

The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6695

Published Dec 2, 2013

The RBAC implementation in Cisco Secure Access Control System (ACS) does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to ob…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6535

Published Dec 2, 2013

DjVuLibre before 3.5.25.3, as used in Evince, Sumatra PDF Reader, VuDroid, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memo…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-0434

Published Dec 2, 2013

The server in Crowbar, as used in SUSE Cloud 1.0, uses weak permissions for the production.log file, which has unspecified impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 451-475 of 5,187 CVEsPage 19 of 208