Total
9170 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-4095 | 1 Imperva | 1 Securesphere | 2013-07-01 | 6.5 MEDIUM | N/A |
plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to execute arbitrary commands via a task with a [command].value field in conjunction with an [arguments].value field. | |||||
CVE-2013-4094 | 1 Imperva | 1 Securesphere | 2013-07-01 | 6.5 MEDIUM | N/A |
The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) private_key or (2) public_key parameter in a T/keyManagement request to plain/settings.html, as demonstrated by uploading a Linux ELF file and a shell script. | |||||
CVE-2013-4660 | 1 Js-yaml Project | 1 Js-yaml | 2013-07-01 | 6.8 MEDIUM | N/A |
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation. | |||||
CVE-2013-3382 | 1 Cisco | 1 Adaptive Security Appliance | 2013-06-27 | 7.8 HIGH | N/A |
The Next-Generation Firewall (aka NGFW, formerly CX Context-Aware Security) module 9.x before 9.1.1.9 and 9.1.2.x before 9.1.2.12 for Cisco Adaptive Security Appliances (ASA) devices allows remote attackers to cause a denial of service (device reload or traffic-processing outage) via fragmented (1) IPv4 or (2) IPv6 traffic, aka Bug ID CSCue88387. | |||||
CVE-2012-4945 | 1 Agilefleet | 2 Fleetcommander, Fleetcommander Kiosk | 2013-06-25 | 7.5 HIGH | N/A |
Agile FleetCommander and FleetCommander Kiosk before 4.08 allow remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection" issue. | |||||
CVE-2013-4636 | 1 Php | 1 Php | 2013-06-24 | 4.3 MEDIUM | N/A |
The mget function in libmagic/softmagic.c in the Fileinfo component in PHP 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (invalid pointer dereference and application crash) via an MP3 file that triggers incorrect MIME type detection during access to an finfo object. | |||||
CVE-2013-4615 | 1 Canon | 9 Mg3100 Printer, Mg5300 Printer, Mg6100 Printer and 6 more | 2013-06-24 | 5.0 MEDIUM | N/A |
The Canon MG3100, MG5300, MG6100, MP495, MX340, MX870, MX890, MX920, and MX922 printers allow remote attackers to cause a denial of service (device hang) via a crafted LAN_TXT24 parameter to English/pages_MacUS/cgi_lan.cgi followed by a direct request to English/pages_MacUS/lan_set_content.html. NOTE: the vendor has apparently responded by stating "Canon believes that its printers will not have to deal with unauthorized access to the network from an external location as long as the printers are used in a secured environment." | |||||
CVE-2013-3378 | 1 Cisco | 2 Telepresence Tc Software, Telepresence Te Software | 2013-06-21 | 7.8 HIGH | N/A |
Cisco TelePresence TC Software before 6.1 and TE Software before 4.1.3 allow remote attackers to cause a denial of service (temporary device hang) via crafted SIP packets, aka Bug ID CSCuf89557. | |||||
CVE-2013-4632 | 1 Huawei | 1 Access Router | 2013-06-20 | 7.8 HIGH | N/A |
The Huawei Access Router (AR) before V200R002SPC003 allows remote attackers to cause a denial of service (device reset) via a crafted field in a DHCP request, as demonstrated by a request from an IP phone. | |||||
CVE-2007-6746 | 1 Canonical | 2 Telepathy-idle, Ubuntu Linux | 2013-06-20 | 5.8 MEDIUM | N/A |
telepathy-idle before 0.1.15 does not verify (1) that the issuer is a trusted CA, (2) that the server hostname matches a domain name in the subject's Common Name (CN), or (3) the expiration date of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |||||
CVE-2013-1203 | 1 Cisco | 1 Asa Cx Context-aware Security Software | 2013-06-18 | 5.4 MEDIUM | N/A |
Cisco ASA CX Context-Aware Security Software allows remote attackers to cause a denial of service (device reload) via crafted TCP packets that appear to have been forwarded by a Cisco Adaptive Security Appliances (ASA) device, aka Bug ID CSCue88386. | |||||
CVE-2012-6567 | 1 Project-redcap | 1 Redcap | 2013-06-17 | 6.5 MEDIUM | N/A |
REDCap before 4.14.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the logic of a custom rule. | |||||
CVE-2013-2783 | 1 Ioserver | 1 Ioserver | 2013-06-16 | 7.1 HIGH | N/A |
The DNP3 driver in IOServer drivers 1.0.19.0 allows remote attackers to cause a denial of service (infinite loop) or obtain unspecified control via crafted data to TCP port 20000. | |||||
CVE-2013-3575 | 1 Hp | 1 Insight Diagnostics | 2013-06-14 | 5.0 MEDIUM | N/A |
hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows remote attackers to include arbitrary hpdiags/frontend2/help/ .html files via the path parameter. | |||||
CVE-2013-3574 | 1 Hp | 1 Insight Diagnostics | 2013-06-14 | 7.8 HIGH | N/A |
Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount) parameter. | |||||
CVE-2013-3376 | 1 Cisco | 1 Video Surveillance Operations Manager | 2013-06-14 | 4.3 MEDIUM | N/A |
Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted URL, aka Bug ID CSCty74490. | |||||
CVE-2013-3573 | 1 Hp | 1 Insight Diagnostics | 2013-06-14 | 10.0 HIGH | N/A |
HP Insight Diagnostics 9.4.0.4710 allows remote attackers to conduct unspecified injection attacks via unknown vectors. | |||||
CVE-2013-1013 | 1 Apple | 1 Safari | 2013-06-05 | 4.3 MEDIUM | N/A |
XSS Auditor in WebKit in Apple Safari before 6.0.5 does not properly rewrite URLs, which allows remote attackers to trigger unintended form submissions via unspecified vectors. | |||||
CVE-2013-3735 | 1 Php | 1 Php | 2013-06-02 | 5.0 MEDIUM | N/A |
** DISPUTED ** The Zend Engine in PHP before 5.4.16 RC1, and 5.5.0 before RC2, does not properly determine whether a parser error occurred, which allows context-dependent attackers to cause a denial of service (memory consumption and application crash) via a crafted function definition, as demonstrated by an attack within a shared web-hosting environment. NOTE: the vendor's http://php.net/security-note.php page says "for critical security situations you should be using OS-level security by running multiple web servers each as their own user id." | |||||
CVE-2013-2315 | 1 Lockon | 1 Ec-cube | 2013-05-29 | 5.0 MEDIUM | N/A |
data/class/pages/forgot/LC_Page_Forgot.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 does not properly validate the input to the password reminder function, which allows remote attackers to obtain sensitive information via a crafted request. |