Total
22706 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-6051 | 1 Quagga | 1 Quagga | 2013-12-16 | 4.3 MEDIUM | N/A |
The bgp_attr_unknown function in bgp_attr.c in Quagga 0.99.21 does not properly initialize the total variable, which allows remote attackers to cause a denial of service (bgpd crash) via a crafted BGP update. | |||||
CVE-2012-3479 | 1 Gnu | 1 Emacs | 2013-12-12 | 6.8 MEDIUM | N/A |
lisp/files.el in Emacs 23.2, 23.3, 23.4, and 24.1 automatically executes eval forms in local-variable sections when the enable-local-variables option is set to :safe, which allows user-assisted remote attackers to execute arbitrary Emacs Lisp code via a crafted file. | |||||
CVE-2011-3950 | 1 Ffmpeg | 1 Ffmpeg | 2013-12-10 | 6.8 MEDIUM | N/A |
The dirac_decode_data_unit function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via a crafted value in the reference pictures number. | |||||
CVE-2011-3949 | 1 Ffmpeg | 1 Ffmpeg | 2013-12-10 | 6.8 MEDIUM | N/A |
The dirac_unpack_idwt_params function in libavcodec/diracdec.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via crafted Dirac data. | |||||
CVE-2011-3935 | 1 Ffmpeg | 1 Ffmpeg | 2013-12-10 | 6.8 MEDIUM | N/A |
The codec_get_buffer function in ffmpeg.c in FFmpeg before 0.10 allows remote attackers to have an unspecified impact via vectors related to a crafted image size. | |||||
CVE-2012-5642 | 1 Fail2ban | 1 Fail2ban | 2013-12-04 | 7.5 HIGH | N/A |
server/action.py in Fail2ban before 0.8.8 does not properly handle the content of the matches tag, which might allow remote attackers to trigger unsafe behavior in a custom action file via unspecified symbols in this content. | |||||
CVE-2012-3363 | 1 Zend | 1 Zend Framework | 2013-12-04 | 6.4 MEDIUM | N/A |
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack. | |||||
CVE-2012-0420 | 1 Opensuse | 1 Zypper | 2013-12-02 | 4.4 MEDIUM | N/A |
zypp-refresh-wrapper in SUSE Zypper before 1.3.20 and 1.6.x before 1.6.166 allows local users to create files in arbitrary directories, or possibly have unspecified other impact, via a pathname in the ZYPP_LOCKFILE_ROOT environment variable. | |||||
CVE-2013-1509 | 1 Oracle | 1 Fusion Middleware | 2013-11-30 | 4.0 MEDIUM | N/A |
Unspecified vulnerability in the Oracle WebCenter Sites component in Oracle Fusion Middleware 7.6.2, 11.1.1.6.0, and 11.1.1.6.1 allows remote authenticated users to affect integrity via unknown vectors related to WebCenter Sites. | |||||
CVE-2013-1747 | 1 Ngircd | 1 Ngircd | 2013-11-30 | 5.0 MEDIUM | N/A |
channel.c in ngIRCd 20 and 20.1 allows remote attackers to cause a denial of service (assertion failure and crash) via a KICK command for a user who is not on the associated channel. | |||||
CVE-2013-6860 | 1 Sybase | 1 Adaptive Server Enterprise | 2013-11-27 | 6.8 MEDIUM | N/A |
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
CVE-2013-6861 | 1 Sybase | 1 Adaptive Server Enterprise | 2013-11-27 | 4.9 MEDIUM | N/A |
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows local users to obtain sensitive information via unspecified vectors. | |||||
CVE-2013-6862 | 1 Sybase | 1 Adaptive Server Enterprise | 2013-11-27 | 7.8 HIGH | N/A |
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified vectors. | |||||
CVE-2013-6867 | 1 Sybase | 1 Adaptive Server Enterprise | 2013-11-25 | 7.1 HIGH | N/A |
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified vectors. | |||||
CVE-2013-6245 | 1 Sybase | 1 Adaptive Server Enterprise | 2013-11-24 | 10.0 HIGH | N/A |
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to execute arbitrary code via unspecified vectors. | |||||
CVE-2013-3243 | 2 Opentext, Sap | 2 Opentext\/ixos Ecm For Sap Netweaver, Netweaver | 2013-11-22 | 6.8 MEDIUM | N/A |
Unspecified vulnerability in OpenText/IXOS ECM for SAP NetWeaver allows remote attackers to execute arbitrary ABAP code via unknown vectors. | |||||
CVE-2013-3238 | 1 Phpmyadmin | 1 Phpmyadmin | 2013-11-18 | 6.0 MEDIUM | N/A |
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace function call within the "Replace table prefix" feature. | |||||
CVE-2013-3063 | 1 Sap | 1 Basis Communication Services | 2013-11-18 | 6.0 MEDIUM | N/A |
SAP BASIS Communication Services 4.6B through 7.30 allows remote authenticated users to execute arbitrary commands via unspecified vectors. | |||||
CVE-2013-3241 | 1 Phpmyadmin | 1 Phpmyadmin | 2013-11-18 | 4.0 MEDIUM | N/A |
export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal array, which allows remote authenticated users to inject values via a crafted request. | |||||
CVE-2013-5990 | 1 Justsystems | 4 Ichitaro, Ichitaro Portable With Oreplug, Ichitaro Pro and 1 more | 2013-11-14 | 9.3 HIGH | N/A |
Unspecified vulnerability in JustSystems Ichitaro 2006 through 2011; Ichitaro Government 6, 7, and 2006 through 2010; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen and Gen Trial Edition; Ichitaro Pro; Ichitaro Pro 2 and Pro 2 Trial Edition; Ichitaro Viewer; and Ichitaro Portable with oreplug allows remote attackers to execute arbitrary code via a crafted document. |