Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 859 High, 2,914 Medium, 517 Low, 1 Unrated.

CVE-2013-0655

Published Jan 21, 2013

The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-6113

Published Jan 19, 2013

The openssl_encrypt function in ext/openssl/openssl.c in PHP 5.3.9 through 5.3.13 does not initialize a certain variable, which allows remote attackers to obtain sensitive informa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5185

Published Jan 19, 2013

Directory traversal vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for iOS allows remote attackers to read or delete files by lev…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5184

Published Jan 19, 2013

Cross-site scripting (XSS) vulnerability in the Olive Toast Documents Pro File Viewer (formerly Files HD) app before 1.11.1 for iOS allows remote attackers to inject arbitrary web…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-5134

Published Jan 18, 2013

Buffer overflow in the "create torrent dialog" functionality in uTorrent 1.8.3 build 15772, and possibly other versions before 1.8.3 (Build 16010), allows user-assisted remote att…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6360

Published Jan 18, 2013

Cross-site scripting (XSS) vulnerability in IBM Intelligent Operations Center 1.5.0 allows remote attackers to inject arbitrary web script or HTML via event data fields.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-6088

Published Jan 18, 2013

The rpmpkgRead function in lib/package.c in RPM 4.10.x before 4.10.2 does not return an error code in certain situations involving an "unparseable signature," which allows remote…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5875

Published Jan 18, 2013

Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5531

Published Jan 18, 2013

Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal in JBoss Enterprise Portal Platform 5.2.2 allow remote attackers to inject arbitrary web script or HTML vi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4607

Published Jan 17, 2013

Buffer overflow in nsrindexd in EMC NetWorker 7.5.x and 7.6.x before 7.6.5, and 8.x before 8.0.0.6, allows remote attackers to execute arbitrary code via crafted SunRPC data.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3310

Published Jan 17, 2013

IBM Tivoli Federated Identity Manager (TFIM) before 6.1.1.14, 6.2.0 before 6.2.0.12, and 6.2.1 before 6.2.1.4 allows context-dependent attackers to discover (1) a cleartext LDAP B…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-0172

Published Jan 17, 2013

Samba 4.0.x before 4.0.1, in certain Active Directory domain-controller configurations, does not properly interpret Access Control Entries that are based on an objectClass, which…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-5429

Published Jan 17, 2013

The VPN driver in Cisco VPN Client on Windows does not properly interact with the kernel, which allows local users to cause a denial of service (kernel fault and system crash) via…

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-5972

Published Jan 17, 2013

Directory traversal vulnerability in the web server in SpecView 2.5 build 853 and earlier allows remote attackers to read arbitrary files via a ... (dot dot dot) in a URI.

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1109

Published Jan 17, 2013

Cross-site request forgery (CSRF) vulnerability in testingLibraryAction.do in the Training Center testing library in Cisco WebEx Training Center allows remote attackers to hijack…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 4,901-4,925 of 5,187 CVEsPage 197 of 208