Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 860 High, 2,913 Medium, 517 Low, 1 Unrated.

CVE-2013-0461

Published Jan 27, 2013

Cross-site scripting (XSS) vulnerability in the virtual member manager (VMM) administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0460

Published Jan 27, 2013

Cross-site request forgery (CSRF) vulnerability in the portlet subsystem in the administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47 and 7.0 before…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0459

Published Jan 27, 2013

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0458

Published Jan 27, 2013

Cross-site scripting (XSS) vulnerability in the Administrative console in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.27, 8.0 before 8.0.0.6, and…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5484

Published Jan 27, 2013

The client in FreeIPA 2.x and 3.x before 3.1.2 does not properly obtain the Certification Authority (CA) certificate from the server, which allows man-in-the-middle attackers to s…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2012-4917

Published Jan 26, 2013

The TripAdvisor app 6.6 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4914

Published Jan 26, 2013

Stack-based buffer overflow in the reader in CoolPDF 3.0.2.256 allows remote attackers to execute arbitrary code via a PDF document with a crafted stream.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0107

Published Jan 26, 2013

Stack-based buffer overflow in Foxit Advanced PDF Editor 3 before 3.04 might allow remote attackers to execute arbitrary code via a crafted document containing instructions that r…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0435

Published Jan 26, 2013

SUSE WebYaST before 1.2 0.2.63-0.6.1 allows remote attackers to modify the hosts list, and subsequently conduct man-in-the-middle attacks, via a crafted /host request on TCP port…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3278

Published Jan 25, 2013

Stack-based buffer overflow in magentservice.exe in HP Diagnostics Server 8.x through 8.07 and 9.x through 9.21 allows remote attackers to execute arbitrary code via a malformed m…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6272

Published Jan 25, 2013

Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.1 allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5689

Published Jan 25, 2013

ISC BIND 9.8.x through 9.8.4-P1 and 9.9.x through 9.9.2-P1, in certain configurations involving DNS64 with a Response Policy Zone that lacks an AAAA rewrite rule, allows remote at…

CVSS 7.1 · High

CVE-2013-1105

Published Jan 24, 2013

Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.3, 7.1 and 7.2 before 7.2.111.3, and 7.3 before 7.3.101.0 allow remote authenticated users to bypass w…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2013-1104

Published Jan 24, 2013

The HTTP Profiling functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.3.101.0 allows remote authenticated users to execute arbitrary code via a crafted H…

CVSS 9.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2013-1103

Published Jan 24, 2013

Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.220.0, 7.1 before 7.1.91.0, and 7.2 before 7.2.103.0 allow remote attackers to cause a denial of service (…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2013-1102

Published Jan 24, 2013

The Wireless Intrusion Prevention System (wIPS) component on Cisco Wireless LAN Controller (WLC) devices with software 7.0 before 7.0.235.0, 7.1 and 7.2 before 7.2.110.0, and 7.3…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2013-0843

Published Jan 24, 2013

content/renderer/media/webrtc_audio_renderer.cc in Google Chrome before 24.0.1312.56 on Mac OS X does not use an appropriate buffer size for the 96 kHz sampling rate, which allows…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-0842

Published Jan 24, 2013

Google Chrome before 24.0.1312.56 does not properly handle %00 characters in pathnames, which has unspecified impact and attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0841

Published Jan 24, 2013

Array index error in the content-blocking functionality in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or possibly have unspecified othe…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-0840

Published Jan 24, 2013

Google Chrome before 24.0.1312.56 does not validate URLs during the opening of new windows, which has unspecified impact and remote attack vectors.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-0839

Published Jan 24, 2013

Use-after-free vulnerability in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors relate…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 4,826-4,850 of 5,187 CVEsPage 194 of 208