Search Results (82398 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-3635 1 Projectpier 1 Projectpier 2024-11-21 5.4 Medium
ProjectPier 0.8.8 has stored XSS
CVE-2013-3628 1 Zabbix 1 Zabbix 2024-11-21 8.8 High
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
CVE-2013-3619 2 Citrix, Supermicro 10 Netscaler, Netscaler Firmware, Netscaler Sd-wan and 7 more 2024-11-21 8.1 High
Intelligent Platform Management Interface (IPMI) with firmware for Supermicro X9 generation motherboards before SMT_X9_317 and firmware for Supermicro X8 generation motherboards before SMT X8 312 contain harcoded private encryption keys for the (1) Lighttpd web server SSL interface and the (2) Dropbear SSH daemon.
CVE-2013-3565 2 Opensuse, Videolan 2 Opensuse, Vlc Media Player 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned in an error message through share/lua/intf/http.lua.
CVE-2013-3542 1 Grandstream 26 Gxv3500, Gxv3500 Firmware, Gxv3501 and 23 more 2024-11-21 10.0 Critical
Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models with firmware 1.0.4.11, have a hardcoded account "!#/" with the same password, which makes it easier for remote attackers to obtain access via a TELNET session.
CVE-2013-3517 1 Netgear 4 Wnr3500l, Wnr3500l Firmware, Wnr3500u and 1 more 2024-11-21 5.4 Medium
Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.
CVE-2013-3492 1 Xnview 1 Xnview 2024-11-21 9.8 Critical
XnView 2.03 has a stack-based buffer overflow vulnerability
CVE-2013-3322 1 Netapp 1 Oncommand System Manager 2024-11-21 7.2 High
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to inject arbitrary commands in the Halt/Reboot interface.
CVE-2013-3320 1 Netapp 1 Oncommand System Manager 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields.
CVE-2013-3247 1 Xnview 1 Xnview 2024-11-21 7.8 High
Heap-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted RLE compressed layer in an XCF file.
CVE-2013-3246 1 Xnview 1 Xnview 2024-11-21 7.8 High
Stack-based buffer overflow in xnview.exe in XnView before 2.03 allows remote attackers to execute arbitrary code via a crafted image layer in an XCF file.
CVE-2013-3214 1 Vtiger 1 Vtiger Crm 2024-11-21 9.8 Critical
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
CVE-2013-3212 1 Vtiger 1 Vtiger Crm 2024-11-21 8.1 High
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
CVE-2013-3097 1 Actiontec 2 Mi424wr-gen3i, Mi424wr-gen3i Firmware 2024-11-21 6.1 Medium
Unspecified Cross-site scripting (XSS) vulnerability in the Verizon FIOS Actiontec MI424WR-GEN3I router.
CVE-2013-3067 1 Linksys 2 Wrt310n, Wrt310n Firmware 2024-11-21 5.4 Medium
Linksys WRT310Nv2 2.0.0.1 is vulnerable to XSS.
CVE-2013-2999 1 Ibm 1 Infosphere Data Replication Dashboard 2024-11-21 N/A
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 84115.
CVE-2013-2739 2 Debian, Readymedia Project 2 Debian Linux, Readymedia 2024-11-21 9.8 Critical
MiniDLNA has heap-based buffer overflow
CVE-2013-2714 1 Podpress Project 1 Podpress 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.
CVE-2013-2684 1 Cisco 2 Linksys E4200, Linksys E4200 Firmware 2024-11-21 6.1 Medium
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVE-2013-2679 1 Belkin 2 Linksys E4200, Linksys E4200 Firmware 2024-11-21 6.1 Medium
Multiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to inject arbitrary web script or HTML via the (1) log_type, (2) ping_ip, (3) ping_size, (4) submit_type, or (5) traceroute_ip parameter to apply.cgi or (6) new_workgroup or (7) submit_button parameter to storage/apply.cgi.