Search Results (24677 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2013-4279 1 Imapsync Project 1 Imapsync 2024-08-06 N/A
imapsync 1.564 and earlier performs a release check by default, which sends sensitive information (imapsync, operating system, and Perl version) to the developer's site.
CVE-2013-4250 1 Typo3 1 Typo3 2024-08-06 N/A
The (1) file upload component and (2) File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.3 do not properly check file extensions, which allow remote authenticated editors to execute arbitrary PHP code by uploading a .php file.
CVE-2013-4361 1 Xen 1 Xen 2024-08-06 N/A
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
CVE-2013-4272 2 Botcha Spam Prevention Project, Drupal 2 Botcha, Drupal 2024-08-06 N/A
The BOTCHA Spam Prevention module 7.x-1.x before 7.x-1.6, 7.x-2.x before 7.x-2.1, and 7.x-3.x before 7.x-3.3 for Drupal, when the debugging level is set to 5 or 6, logs the content of submitted forms, which allows context-dependent users to obtain sensitive information such as usernames and passwords by reading the log file.
CVE-2013-4254 1 Linux 1 Linux Kernel 2024-08-06 N/A
The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event.
CVE-2013-4195 1 Plone 1 Plone 2024-08-06 N/A
Multiple open redirect vulnerabilities in (1) marmoset_patch.py, (2) publish.py, and (3) principiaredirect.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2013-4242 5 Canonical, Debian, Gnupg and 2 more 6 Ubuntu Linux, Debian Linux, Gnupg and 3 more 2024-08-06 N/A
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
CVE-2013-4255 2 Condor Project, Redhat 2 Condor, Enterprise Mrg 2024-08-06 N/A
The policy definition evaluator in Condor 7.5.4, 8.0.0, and earlier does not properly handle attributes in a (1) PREEMPT, (2) SUSPEND, (3) CONTINUE, (4) WANT_VACATE, or (5) KILL policy that evaluate to an Unconfigured, Undefined, or Error state, which allows remote authenticated users to cause a denial of service (condor_startd exit) via a crafted job.
CVE-2013-4165 1 Bitcoin 1 Bitcoin Core 2024-08-06 N/A
The HTTPAuthorized function in bitcoinrpc.cpp in bitcoind 0.8.1 provides information about authentication failure upon detecting the first incorrect byte of a password, which makes it easier for remote attackers to determine passwords via a timing side-channel attack.
CVE-2013-4245 2 Debian, Gnome 2 Debian Linux, Orca 2024-08-06 7.3 High
Orca has arbitrary code execution due to insecure Python module load
CVE-2013-4183 2 Openstack, Redhat 2 Cinder, Openstack 2024-08-06 N/A
The clear_volume function in LVMVolumeDriver driver in OpenStack Cinder 2013.1.1 through 2013.1.2 does not properly clear data when deleting a snapshot, which allows local users to obtain sensitive information via unspecified vectors.
CVE-2013-4199 1 Plone 1 Plone 2024-08-06 N/A
(1) cb_decode.py and (2) linkintegrity.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users to cause a denial of service (resource consumption) via a large zip archive, which is expanded (decompressed).
CVE-2013-4187 1 Flippy Project 1 Flippy 2024-08-06 6.5 Medium
The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote authenticated users with the permission to access content to read a link or alias to a restricted node.
CVE-2013-4197 1 Plone 1 Plone 2024-08-06 N/A
member_portrait.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote authenticated users to modify or delete portraits of other users via unspecified vectors.
CVE-2013-4180 2 Redhat, Theforeman 4 Openstack, Satellite, Satellite Capsule and 1 more 2024-08-06 N/A
The (1) power and (2) ipmi_boot actions in the HostController in Foreman before 1.2.2 allow remote attackers to cause a denial of service (memory consumption) via unspecified input that is converted to a symbol.
CVE-2013-4166 2 Gnome, Redhat 6 Evolution, Evolution Data Server, Enterprise Linux and 3 more 2024-08-06 7.5 High
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email encryption, which might cause the email to be encrypted with the wrong key and allow remote attackers to obtain sensitive information.
CVE-2013-4176 1 Mysecureshell Project 1 Mysecureshell 2024-08-06 5.5 Medium
mysecureshell 1.31: Local Information Disclosure Vulnerability
CVE-2013-4144 1 Swfupload Project 1 Swfupload 2024-08-06 9.8 Critical
There is an object injection vulnerability in swfupload plugin for wordpress.
CVE-2013-4101 1 Cryptocat Project 1 Cryptocat 2024-08-06 5.3 Medium
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
CVE-2013-4105 1 Cryptocat Project 1 Cryptocat 2024-08-06 7.5 High
Cryptocat before 2.0.22 has Multiparty Encryption Scheme Information Disclosure