Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 859 High, 2,914 Medium, 517 Low, 1 Unrated.

CVE-2012-6505

Published Jan 24, 2013

Cross-site scripting (XSS) vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to inject arbitrary web script or HTML via the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6504

Published Jan 24, 2013

SQL injection vulnerability in mods/hours/data/get_hours.php in PHP Volunteer Management 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6085

Published Jan 24, 2013

The read_block function in g10/import.c in GnuPG 1.4.x before 1.4.13 and 2.0.x through 2.0.19, when importing a key, allows remote attackers to corrupt the public keyring database…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2099

Published Jan 24, 2013

Multiple cross-site scripting (XSS) vulnerabilities in Wikidforum 2.10 allow remote attackers to inject arbitrary web script or HTML via the (1) search field, or the (2) Author or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1922

Published Jan 24, 2013

Multiple cross-site request forgery (CSRF) vulnerabilities in Sitecom WLM-2501 allow remote attackers to hijack the authentication of administrators for requests that modify setti…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0209

Published Jan 23, 2013

lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote at…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-6096

Published Jan 22, 2013

Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5616

Published Jan 22, 2013

Apache CloudStack 4.0.0-incubating and Citrix CloudPlatform (formerly Citrix CloudStack) before 3.0.6 stores sensitive information in the log4j.conf log file, which allows local u…

CVSS 1.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4918

Published Jan 22, 2013

Call of Duty Elite for iOS 2.0.1 does not properly validate the server SSL certificate, which allows remote attackers to obtain sensitive information via a Man-in-the-Middle (MITM…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4461

Published Jan 22, 2013

The KVM subsystem in the Linux kernel before 3.6.9, when running on hosts that use qemu userspace without XSAVE, allows local users to cause a denial of service (kernel OOPS) by u…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4414

Published Jan 22, 2013

Multiple SQL injection vulnerabilities in the replication code in Oracle MySQL possibly before 5.5.29, and MariaDB 5.1.x through 5.1.62, 5.2.x through 5.2.12, 5.3.x through 5.3.7,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3364

Published Jan 22, 2013

Multiple stack-based buffer overflows in the Near Field Communication Controller Interface (NCI) in the Linux kernel before 3.4.5 allow remote attackers to cause a denial of servi…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2372

Published Jan 22, 2013

The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a de…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2137

Published Jan 22, 2013

Buffer overflow in virt/kvm/irq_comm.c in the KVM subsystem in the Linux kernel before 3.2.24 allows local users to cause a denial of service (crash) and possibly execute arbitrar…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-2119

Published Jan 22, 2013

Buffer overflow in the macvtap device driver in the Linux kernel before 3.4.5, when running in certain configurations, allows privileged KVM guest users to cause a denial of servi…

CVSS 5.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6502

Published Jan 22, 2013

Microsoft Internet Explorer before 10 allows remote attackers to obtain sensitive information about the existence of files, and read certain data from files, via a UNC share pathn…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1110

Published Jan 21, 2013

Cisco WebEx Training Center allow remote authenticated users to bypass intended privilege restrictions and (1) enable or (2) disable training-center recordings via a crafted URL,…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1108

Published Jan 21, 2013

Cisco WebEx Training Center allows remote authenticated users to remove hands-on lab-session reservations via a crafted URL, aka Bug ID CSCzu81064.

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0929

Published Jan 21, 2013

Format string vulnerability in the _vsnsprintf function in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary cod…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2013-0928

Published Jan 21, 2013

The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary commands via a DCP "run com…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6069

Published Jan 21, 2013

The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope.…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6068

Published Jan 21, 2013

The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 4,876-4,900 of 5,187 CVEsPage 196 of 208