Total
9170 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-1151 | 1 Cisco | 1 Adaptive Security Appliance Software | 2013-04-11 | 7.1 HIGH | N/A |
Cisco Adaptive Security Appliances (ASA) devices with software 7.x before 7.2(5.10), 8.0 before 8.0(5.31), 8.1 and 8.2 before 8.2(5.38), 8.3 before 8.3(2.37), 8.4 before 8.4(5), 8.5 before 8.5(1.17), 8.6 before 8.6(1.10), and 8.7 before 8.7(1.3) allow remote attackers to cause a denial of service (device reload) via a crafted certificate, aka Bug ID CSCuc72408. | |||||
CVE-2013-1172 | 1 Cisco | 1 Anyconnect Secure Mobility Client | 2013-04-11 | 6.6 MEDIUM | N/A |
The Cisco Security Service in Cisco AnyConnect Secure Mobility Client (aka AnyConnect VPN Client) does not properly verify files, which allows local users to gain privileges via unspecified vectors, aka Bug ID CSCud14153. | |||||
CVE-2013-1189 | 1 Cisco | 1 Ubr10012 | 2013-04-11 | 5.7 MEDIUM | N/A |
Cisco Universal Broadband (aka uBR) 10000 series routers, when an IPv4/IPv6 dual-stack modem is used, allow remote attackers to cause a denial of service (routing-engine reload) via unspecified changes to IP address assignments, aka Bug ID CSCue15313. | |||||
CVE-2013-2503 | 1 Privoxy | 1 Privoxy | 2013-04-10 | 5.8 MEDIUM | N/A |
Privoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which makes it easier for remote HTTP servers to spoof the intended proxy service via a 407 (aka Proxy Authentication Required) HTTP status code. | |||||
CVE-2012-5049 | 1 Optimalog | 1 Optima Plc | 2013-04-10 | 7.8 HIGH | N/A |
APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed packet. | |||||
CVE-2012-3443 | 1 Djangoproject | 1 Django | 2013-04-10 | 5.0 MEDIUM | N/A |
The django.forms.ImageField class in the form system in Django before 1.3.2 and 1.4.x before 1.4.1 completely decompresses image data during image validation, which allows remote attackers to cause a denial of service (memory consumption) by uploading an image file. | |||||
CVE-2013-0681 | 2 Cogentdatahub, Microsoft | 5 Cascade Datahub, Cogent Datahub, Datahub Quicktrend and 2 more | 2013-04-08 | 5.0 MEDIUM | N/A |
Cogent Real-Time Systems Cogent DataHub before 7.3.0, OPC DataHub before 6.4.22, Cascade DataHub before 6.4.22 on Windows, and DataHub QuickTrend before 7.3.0 allow remote attackers to cause a denial of service (NULL pointer dereference and application crash) via malformed data in a formatted text command. | |||||
CVE-2012-1177 | 1 Gnome | 1 Libgdata | 2013-04-04 | 5.1 MEDIUM | N/A |
libgdata before 0.10.2 and 0.11.x before 0.11.1 does not validate SSL certificates, which allows remote attackers to obtain user names and passwords via a man-in-the-middle (MITM) attack with a spoofed certificate. | |||||
CVE-2012-4710 | 1 Invensys | 1 Wonderware Win-xml Exporter | 2013-04-04 | 9.3 HIGH | N/A |
Invensys Wonderware Win-XML Exporter 1522.148.0.0 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference. | |||||
CVE-2013-1162 | 1 Cisco | 1 Ios Xr | 2013-03-26 | 5.0 MEDIUM | N/A |
The traffic engineering (TE) processing subsystem in Cisco IOS XR allows remote attackers to cause a denial of service (process restart) via crafted TE packets, aka Bug ID CSCue04000. | |||||
CVE-2013-1161 | 1 Cisco | 1 Jabber Im | 2013-03-26 | 6.3 MEDIUM | N/A |
The XML parser in the Cisco Jabber IM application for Android allows remote authenticated users to cause a denial of service (blocked connection) by leveraging an entry on a Buddy list and sending a crafted XMPP presence update message, aka Bug ID CSCue38383. | |||||
CVE-2013-1135 | 1 Cisco | 1 Prime Central For Hosted Collaboration Solution Assurance | 2013-03-22 | 7.1 HIGH | N/A |
Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance 8.6 and 9.0 allows remote attackers to cause a denial of service (CPU consumption and monitoring outage) via malformed TLS messages to TCP port (1) 9043 or (2) 9443, aka Bug ID CSCuc07155. | |||||
CVE-2013-0669 | 1 Siemens | 1 Wincc Tia Portal | 2013-03-21 | 4.0 MEDIUM | N/A |
The HMI web application in Siemens WinCC (TIA Portal) 11 allows remote authenticated users to cause a denial of service (daemon crash) via a crafted HTTP request. | |||||
CVE-2013-0670 | 1 Siemens | 1 Wincc Tia Portal | 2013-03-21 | 4.3 MEDIUM | N/A |
CRLF injection vulnerability in the HMI web application in Siemens WinCC (TIA Portal) 11 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL. | |||||
CVE-2012-3696 | 1 Apple | 1 Safari | 2013-03-21 | 4.3 MEDIUM | N/A |
CRLF injection vulnerability in WebKit in Apple Safari before 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP request splitting attacks via a crafted web site that leverages improper WebSockets URI handling. | |||||
CVE-2013-0712 | 1 Windriver | 1 Vxworks | 2013-03-20 | 6.8 MEDIUM | N/A |
IPSSH (aka the SSH server) in Wind River VxWorks 6.5 through 6.9 allows remote authenticated users to cause a denial of service (daemon outage) via a crafted packet. | |||||
CVE-2013-0963 | 1 Apple | 1 Iphone Os | 2013-03-15 | 2.1 LOW | N/A |
Identity Services in Apple iOS before 6.1 does not properly handle validation failures of AppleID certificates, which might allow physically proximate attackers to bypass authentication by leveraging an incorrect assignment of an empty string value to an AppleID. | |||||
CVE-2012-4348 | 1 Symantec | 1 Endpoint Protection | 2013-03-13 | 7.2 HIGH | N/A |
The management console in Symantec Endpoint Protection (SEP) 11.0 before RU7-MP3 and 12.1 before RU2, and Symantec Endpoint Protection Small Business Edition 12.x before 12.1 RU2, does not properly validate input for PHP scripts, which allows remote authenticated users to execute arbitrary code via unspecified vectors. | |||||
CVE-2012-5703 | 1 Vmware | 2 Esx, Esxi | 2013-03-11 | 5.0 MEDIUM | N/A |
The vSphere API in VMware ESXi 4.1 and ESX 4.1 allows remote attackers to cause a denial of service (host daemon crash) via an invalid value in a (1) RetrieveProp or (2) RetrievePropEx SOAP request. | |||||
CVE-2013-1621 | 1 Polarssl | 1 Polarssl | 2013-03-07 | 4.3 MEDIUM | N/A |
Array index error in the SSL module in PolarSSL before 1.2.5 might allow remote attackers to cause a denial of service via vectors involving a crafted padding-length value during validation of CBC padding in a TLS session, a different vulnerability than CVE-2013-0169. |