Latest CVE Feed
-
7.1
HIGHCVE-2013-4602
A Denial of Service (infinite loop) vulnerability exists in Avira AntiVir Engine before 8.2.12.58 via an unspecified function in the PDF Scanner Engine.... Read more
- EPSS Score: %0.26
- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4593
RubyGem omniauth-facebook has an access token security vulnerability... Read more
Affected Products : omniauth-facebook- EPSS Score: %0.35
- Published: Dec. 11, 2019
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2013-4584
Perdition before 2.2 may have weak security when handling outbound connections, caused by an error in the STARTTLS IMAP and POP server. ssl_outgoing_ciphers not being applied to STARTTLS connections... Read more
- EPSS Score: %0.58
- Published: Nov. 15, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-4583
The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositori... Read more
- EPSS Score: %0.29
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2013-4582
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote aut... Read more
- EPSS Score: %0.16
- Published: Jan. 28, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4572
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.... Read more
- EPSS Score: %1.02
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2013-4561
In a openshift node, there is a cron job to update mcollective facts that mishandles a temporary file. This may lead to loss of confidentiality and integrity.... Read more
Affected Products : openshift- EPSS Score: %0.31
- Published: Jun. 30, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-4536
An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the p... Read more
Affected Products : qemu- EPSS Score: %0.04
- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-4535
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.... Read more
- EPSS Score: %0.38
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-4532
Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.... Read more
- EPSS Score: %0.23
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4521
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: t... Read more
Affected Products : nuxeo- EPSS Score: %2.55
- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4518
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates... Read more
- EPSS Score: %0.08
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- EPSS Score: %0.60
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2013-4462
WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability... Read more
Affected Products : portable_phpmyadmin- EPSS Score: %1.19
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2013-4454
WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities... Read more
- EPSS Score: %0.88
- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4451
gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.... Read more
Affected Products : gitolite- EPSS Score: %1.96
- Published: Sep. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4441
The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.... Read more
Affected Products : pwgen- EPSS Score: %0.43
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4423
CloudForms stores user passwords in recoverable format... Read more
Affected Products : cloudforms- EPSS Score: %0.10
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4412
slim has NULL pointer dereference when using crypt() method from glibc 2.17... Read more
- EPSS Score: %0.94
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4411
Review Board: URL processing gives unauthorized users access to review lists... Read more
- EPSS Score: %0.51
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024