Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 860 High, 2,913 Medium, 517 Low, 1 Unrated.

CVE-2012-6095

Published Jan 24, 2013

ProFTPD before 1.3.5rc1, when using the UserOwner directive, allows local users to modify the ownership of arbitrary files via a race condition and a symlink attack on the (1) MKD…

CVSS 1.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5670

Published Jan 24, 2013

The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) via vectors related to BDF…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5669

Published Jan 24, 2013

The _bdf_parse_glyphs function in FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors re…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5668

Published Jan 24, 2013

FreeType before 2.4.11 allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to BDF fonts and the improper handl…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6521

Published Jan 24, 2013

Cross-site scripting (XSS) vulnerability in apps/admin/handlers/versions.php in Elefant CMS 1.2.0 allows remote attackers to inject arbitrary web script or HTML via the id paramet…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6520

Published Jan 24, 2013

Multiple SQL injection vulnerabilities in the advanced search in Wikidforum 2.10 allow remote attackers to execute arbitrary SQL commands via the (1) select_sort or (2) opt_search…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6519

Published Jan 24, 2013

SQL injection vulnerability in modules/poll/index.php in DIY-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter to mod.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6518

Published Jan 24, 2013

Cross-site request forgery (CSRF) vulnerability in mod.php in DiY-CMS 1.0 allows remote attackers to hijack the authentication of administrators for requests that create a poll vi…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6517

Published Jan 24, 2013

Multiple cross-site scripting (XSS) vulnerabilities in DiY-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) question parameter to in /modules/poll…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6516

Published Jan 24, 2013

SQL injection vulnerability in PHP Ticket System Beta 1 allows remote attackers to execute arbitrary SQL commands via the q parameter to index.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6515

Published Jan 24, 2013

eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, whi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6513

Published Jan 24, 2013

Cross-site scripting (XSS) vulnerability in index.php/Admin_Preferences in gpEasy CMS 2.3.3 allows remote attackers to inject arbitrary web script or HTML via the jsoncallback par…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6512

Published Jan 24, 2013

The Organizer plugin 1.2.1 for WordPress allows remote attackers to obtain the installation path via unspecified vectors to (1) plugin_hook.php, (2) page/index.php, (3) page/dir.p…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6511

Published Jan 24, 2013

Multiple cross-site scripting (XSS) vulnerabilities in organizer/page/users.php in the Organizer plugin 1.2.1 for WordPress allow remote attackers to inject arbitrary web script o…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6510

Published Jan 24, 2013

Multiple cross-site scripting (XSS) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) PWRS or (2) Descriptio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6509

Published Jan 24, 2013

Unrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP code by uploading a file a double extension, as demonstrated…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6508

Published Jan 24, 2013

Multiple cross-site request forgery (CSRF) vulnerabilities in NetArt Media Car Portal 3.0 allow remote attackers to hijack the authentication of administrators for requests that (…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6507

Published Jan 24, 2013

Multiple SQL injection vulnerabilities in admin.php in ChurchCMS 0.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameters in a login…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 4,851-4,875 of 5,187 CVEsPage 195 of 208