Skip to main content

Year archive

CVEs published in 2013

Archive summary

5,187 CVEs published in 2013 — 896 Critical, 859 High, 2,914 Medium, 517 Low, 1 Unrated.

CVE-2012-0427

Published Dec 2, 2013

yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 allows local users to gain privileges via a crafted (1) file…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0425

Published Dec 2, 2013

LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows context-dependent attackers to obtai…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2012-0420

Published Dec 2, 2013

zypp-refresh-wrapper in SUSE Zypper before 1.3.20 and 1.6.x before 1.6.166 allows local users to create files in arbitrary directories, or possibly have unspecified other impact,…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0414

Published Dec 2, 2013

Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11 SP1 allows remote attackers to inject arbitrary web script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3707

Published Dec 1, 2013

The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intende…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-2818

Published Dec 1, 2013

The DNP Master Driver in Alstom e-terracontrol 3.5, 3.6, and 3.7 allows physically proximate attackers to cause a denial of service (infinite loop and DNP3 service disruption) via…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6718

Published Dec 1, 2013

The Advanced Management Module (AMM) with firmware 3.64B, 3.64C, and 3.64G for IBM BladeCenter systems allows remote attackers to discover account names and passwords via use of a…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3708

Published Dec 1, 2013

The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6918

Published Nov 30, 2013

The web interface on the Satechi travel router 1.5, when Wi-Fi is used for WAN access, exposes the console without authentication on the WAN IP address regardless of the "Web Mana…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-5636

Published Nov 30, 2013

Unlock.exe in Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not associate password failures with a device ID, which makes it easier for physic…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-5635

Published Nov 30, 2013

Media Encryption EPM Explorer in Check Point Endpoint Security through E80.50 does not properly maintain the state of password failures, which makes it easier for physically proxi…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-6392

Published Nov 30, 2013

The genlock_dev_ioctl function in genlock.c in the Genlock driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6706

Published Nov 29, 2013

The Cisco Express Forwarding processing module in Cisco IOS XE allows remote attackers to cause a denial of service (device reload) via crafted MPLS packets that are not properly…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6700

Published Nov 29, 2013

The SNMP module in Cisco IOS XR allows remote attackers to cause a denial of service (process reload) via a request for an unspecified MIB, aka Bug ID CSCuh43144.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4844

Published Nov 29, 2013

Unspecified vulnerability in HP Service Manager 7.11, 9.21, 9.30, 9.31, and 9.32, and ServiceCenter 6.2.8, allows remote attackers to execute arbitrary code via unknown vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-5065

Published Nov 28, 2013

NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in Nove…

CVSS 7.8 · High
evidence mentions
6
Buzz score
54.0
KEV listed
Vendor/product tagsBeta · best-effort
Showing 476-500 of 5,187 CVEsPage 20 of 208