| alstom -- e-terracontrol |
The DNP Master Driver in Alstom e-terracontrol 3.5, 3.6, and 3.7 allows physically proximate attackers to cause a denial of service (infinite loop and DNP3 service disruption) via crafted input over a serial line. |
2013年12月01日 |
4.7 |
CVE-2013-2818 |
| att -- connect_participant_application |
Stack-based buffer overflow in the AT&T Connect Participant Application before 9.5.51 on Windows allows remote attackers to execute arbitrary code via a malformed .SVT file. |
2013年12月04日 |
6.8 |
CVE-2013-6029 |
| cisco -- prime_collaboration |
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Assurance component in Cisco Prime Collaboration allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka Bug IDs CSCui92643, CSCui94038, and CSCui94161. |
2013年12月03日 |
4.3 |
CVE-2013-6690 |
| cisco -- secure_access_control_system |
The RBAC implementation in Cisco Secure Access Control System (ACS) does not properly verify privileges for support-bundle downloads, which allows remote authenticated users to obtain sensitive information via a download action, as demonstrated by obtaining read access to the user database, aka Bug ID CSCuj39274. |
2013年12月02日 |
4.0 |
CVE-2013-6695 |
| cisco -- ons_15454 |
The management implementation on Cisco ONS 15454 controller cards with software 9.8 and earlier allows remote attackers to cause a denial of service (card reset) via crafted packets, aka Bug ID CSCtz50902. |
2013年12月04日 |
4.3 |
CVE-2013-6702 |
| cisco -- ios |
The IP Device Tracking (IPDT) feature in Cisco IOS and IOS XE allows remote attackers to cause a denial of service (IPDT AVL corruption and device reload) via a crafted sequence of ARP packets, aka Bug ID CSCuh38133. |
2013年12月03日 |
6.1 |
CVE-2013-6705 |
| claroline -- claroline |
Multiple cross-site scripting (XSS) vulnerabilities in Claroline before 1.11.9 allow remote attackers to inject arbitrary web script or HTML via the (1) box parameter to messaging/messagebox.php, cidToEdit parameter to (2) adminregisteruser.php or (3) admin_user_course_settings.php in admin/, (4) module_id parameter to admin/module/module.php, or (5) offset parameter to admin/right/profile_list.php. |
2013年12月05日 |
4.3 |
CVE-2013-6267 |
| cybozu -- garoon |
The server in Cybozu Garoon before 3.7 SP1 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors. |
2013年12月05日 |
5.0 |
CVE-2013-6002 |
| cybozu -- garoon |
CRLF injection vulnerability in Cybozu Garoon 3.1 through 3.5 SP5, when Phone Messages forwarding is enabled, allows remote authenticated users to inject arbitrary e-mail headers via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6003 |
| cybozu -- garoon |
Session fixation vulnerability in Cybozu Garoon before 3.7.2 allows remote attackers to hijack web sessions via unspecified vectors. |
2013年12月05日 |
6.8 |
CVE-2013-6004 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in the system-administration component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6900 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0, when Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6901 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in the Space function in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6902 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in a schedule component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6903 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in a note component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6904 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in a phone component in Cybozu Garoon before 3.7.0, when Internet Explorer or Firefox is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6905 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon before 3.7.0, when Internet Explorer 6 through 8 is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6906 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 2.x and 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6907 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in a mail component in Cybozu Garoon 3.x before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6908 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in a report component in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6909 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in Ajax components in Cybozu Garoon before 3.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6910 |
| cybozu -- garoon |
Cross-site scripting (XSS) vulnerability in the Yahoo! User Interface Library in Cybozu Garoon before 3.7.2, when Internet Explorer 9 or 10 or Chrome is used, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月05日 |
4.3 |
CVE-2013-6916 |
| elecsyscorp -- director_industrial_communication_gateway |
The DNP3 service in the Outstation component on Elecsys Director Gateway devices with kernel 2.6.32.11ael1 and earlier allows remote attackers to cause a denial of service (CPU consumption and communication outage) via crafted input. |
2013年12月04日 |
4.3 |
CVE-2013-2825 |
| ganglia -- ganglia-web |
Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php. |
2013年12月05日 |
4.3 |
CVE-2013-6395 |
| ibm -- filenet_content_manager |
Cross-site scripting (XSS) vulnerability in workingSet.jsp in IBM Eclipse Help System (IEHS), as used in the installable InfoCenter component in IBM FileNet Content Manager 4.5.1, 5.0.0, 5.1.0, and 5.2.0, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. |
2013年12月04日 |
4.3 |
CVE-2013-5449 |
| ibm -- qradar_security_information_and_event_manager |
The WinCollect agent in IBM Security QRadar SIEM before 7.1.1.569824 allows remote attackers to bypass intended access restrictions by injecting a (1) DLL or (2) configuration file. |
2013年11月29日 |
4.3 |
CVE-2013-5463 |
| ibm -- advanced_management_module_firmware |
The Advanced Management Module (AMM) with firmware 3.64B, 3.64C, and 3.64G for IBM BladeCenter systems allows remote attackers to discover account names and passwords via use of an unspecified interface. |
2013年11月30日 |
6.4 |
CVE-2013-6718 |
| jamroom -- search_module |
Cross-site scripting (XSS) vulnerability in the Search module before 1.1.1 for Jamroom allows remote attackers to inject arbitrary web script or HTML via the search_string parameter to search/results/all/1/4. |
2013年12月05日 |
4.3 |
CVE-2013-6804 |
| linux -- linux_kernel |
The genlock_dev_ioctl function in genlock.c in the Genlock driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted GENLOCK_IOC_EXPORT ioctl call. |
2013年11月29日 |
4.9 |
CVE-2013-6392 |
| microsoft -- enhanced_mitigation_experience_toolkit |
Microsoft Enhanced Mitigation Experience Toolkit (EMET) before 4.0 uses predictable addresses for hooked functions, which makes it easier for context-dependent attackers to defeat the ASLR protection mechanism via a return-oriented programming (ROP) attack. |
2013年11月29日 |
4.3 |
CVE-2013-6791 |
| novell -- suse_manager |
Cross-site scripting (XSS) vulnerability in the Spacewalk service in SUSE Manager 1.2 for SUSE Linux Enterprise (SLE) 11 SP1 allows remote attackers to inject arbitrary web script or HTML via an image name. |
2013年12月01日 |
4.3 |
CVE-2012-0414 |
| novell -- open_enterprise_server |
The HTTPSTK service in the novell-nrm package before 2.0.2-297.305.302.3 in Novell Open Enterprise Server 2 (OES 2) Linux, and OES 11 Linux Gold and SP1, does not make the intended SSL_free and SSL_shutdown calls for the close of a TCP connection, which allows remote attackers to cause a denial of service (service crash) by establishing many TCP connections to port 8009. |
2013年12月01日 |
4.3 |
CVE-2013-3707 |
| novell -- iprint |
The id1.GetPrinterURLList function in Novell iPrint Client before 5.93 allows remote attackers to cause a denial of service via unspecified vectors. |
2013年11月30日 |
5.0 |
CVE-2013-3708 |
| opensuse -- zypper |
zypp-refresh-wrapper in SUSE Zypper before 1.3.20 and 1.6.x before 1.6.166 allows local users to create files in arbitrary directories, or possibly have unspecified other impact, via a pathname in the ZYPP_LOCKFILE_ROOT environment variable. |
2013年12月01日 |
4.4 |
CVE-2012-0420 |
| redhat -- jboss_enterprise_application_platform |
The EJB invocation handler implementation in Red Hat JBossWS, as used in JBoss Enterprise Application Platform (EAP) before 6.2.0, does not properly enforce the method level restrictions for JAX-WS Service endpoints, which allows remote authenticated users to access otherwise restricted JAX-WS handlers by leveraging permissions to the EJB class. |
2013年12月06日 |
4.9 |
CVE-2013-2133 |
| rockmongo -- rockmongo |
Multiple cross-site scripting (XSS) vulnerabilities in the xn function in RockMongo 1.1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) db parameter on the login page or (2) username parameter in a login.index action to index.php and other unspecified parameters. |
2013年12月05日 |
4.3 |
CVE-2013-5108 |
| satechi -- smart_travel_router |
The web interface on the Satechi travel router 1.5, when Wi-Fi is used for WAN access, exposes the console without authentication on the WAN IP address regardless of the "Web Management via WAN" setting, which allows remote attackers to bypass intended access restrictions via HTTP requests. |
2013年11月30日 |
5.8 |
CVE-2013-6918 |
| videocharge -- watermark_master |
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the SourcePath value in a .wcf file. |
2013年12月04日 |
6.8 |
CVE-2013-6935 |
| videocharge -- watermark_master |
Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the cols element name attribute in a .wstyle file. |
2013年12月04日 |
6.8 |
CVE-2013-6937 |
| vmware -- fusion |
lgtosync.sys in VMware Workstation 9.x before 9.0.3, VMware Player 5.x before 5.0.3, VMware Fusion 5.x before 5.0.4, VMware ESXi 4.0 through 5.1, and VMware ESX 4.0 and 4.1, when a 32-bit Windows guest OS is used, allows guest OS users to gain guest OS privileges via an application that performs a crafted memory allocation. |
2013年12月04日 |
6.9 |
CVE-2013-3519 |