Search Results (23483 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-4856 1 Dlink 2 Dir-865l, Dir-865l Firmware 2024-11-21 6.5 Medium
D-Link DIR-865L has Information Disclosure.
CVE-2013-4751 3 Fedoraproject, Redhat, Sensiolabs 3 Fedora, Enterprise Linux, Symfony 2024-11-21 8.1 High
php-symfony2-Validator has loss of information during serialization
CVE-2013-4535 2 Qemu, Redhat 8 Qemu, Enterprise Linux, Enterprise Linux Desktop and 5 more 2024-11-21 8.8 High
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
CVE-2013-4518 1 Redhat 2 Enterprise Linux, Update Infrastructure 2024-11-21 5.5 Medium
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
CVE-2013-4409 3 Fedoraproject, Redhat, Reviewboard 4 Fedora, Enterprise Linux, Djblets and 1 more 2024-11-21 9.8 Critical
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
CVE-2013-4317 1 Apache 1 Cloudstack 2024-11-21 N/A
In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.
CVE-2013-4245 2 Debian, Gnome 2 Debian Linux, Orca 2024-11-21 7.3 High
Orca has arbitrary code execution due to insecure Python module load
CVE-2013-4209 1 Redhat 1 Automatic Bug Reporting Tool 2024-11-21 N/A
Automatic Bug Reporting Tool (ABRT) before 2.1.6 allows local users to obtain sensitive information about arbitrary files via vectors related to sha1sums.
CVE-2013-4187 1 Flippy Project 1 Flippy 2024-11-21 6.5 Medium
The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote authenticated users with the permission to access content to read a link or alias to a restricted node.
CVE-2013-4176 1 Mysecureshell Project 1 Mysecureshell 2024-11-21 5.5 Medium
mysecureshell 1.31: Local Information Disclosure Vulnerability
CVE-2013-4166 2 Gnome, Redhat 6 Evolution, Evolution Data Server, Enterprise Linux and 3 more 2024-11-21 7.5 High
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
CVE-2013-4144 1 Swfupload Project 1 Swfupload 2024-11-21 9.8 Critical
There is an object injection vulnerability in swfupload plugin for wordpress.
CVE-2013-4110 1 Cryptocat Project 1 Cryptocat 2024-11-21 5.3 Medium
Cryptocat has an Unspecified Chat Participant User List Disclosure
CVE-2013-4105 1 Cryptocat Project 1 Cryptocat 2024-11-21 7.5 High
Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure
CVE-2013-4103 1 Cryptocat Project 1 Cryptocat 2024-11-21 9.8 Critical
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
CVE-2013-4101 1 Cryptocat Project 1 Cryptocat 2024-11-21 5.3 Medium
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
CVE-2013-4100 1 Cryptocat Project 1 Cryptocat 2024-11-21 7.5 High
Cryptocat before 2.0.22 has Remote Denial of Service via username
CVE-2013-4088 1 Otrs 1 Otrs 2024-11-21 6.5 Medium
Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote attackers with a valid agent login to read restricted tickets via a crafted URL involving the ticket split mechanism.
CVE-2013-3945 1 Extensis 1 Mrsid 2024-11-21 7.8 High
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.
CVE-2013-3738 1 Zabbix 1 Zabbix 2024-11-21 9.8 Critical
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.