Latest CVE Feed
-
7.8
HIGHCVE-2013-4536
An user able to alter the savevm data (either on the disk or over the wire during migration) could use this flaw to to corrupt QEMU process memory on the (destination) host, which could potentially result in arbitrary code execution on the host with the p... Read more
Affected Products : qemu- Published: May. 28, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2013-4535
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.... Read more
- Published: Feb. 11, 2020
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-4532
Qemu 1.1.2+dfsg to 2.1+dfsg suffers from a buffer overrun which could potentially result in arbitrary code execution on the host with the privileges of the QEMU process.... Read more
- Published: Jan. 02, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4521
RichFaces implementation in Nuxeo Platform 5.6.0 before HF27 and 5.8.0 before HF-01 does not restrict the classes for which deserialization methods can be called, which allows remote attackers to execute arbitrary code via crafted serialized data. NOTE: t... Read more
Affected Products : nuxeo- Published: Feb. 06, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4518
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates... Read more
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICAL- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2013-4462
WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability... Read more
Affected Products : portable_phpmyadmin- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2013-4454
WordPress Portable phpMyAdmin Plugin 1.4.1 has Multiple Security Bypass Vulnerabilities... Read more
- Published: Feb. 18, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4451
gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.... Read more
Affected Products : gitolite- Published: Sep. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4441
The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.... Read more
Affected Products : pwgen- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2013-4423
CloudForms stores user passwords in recoverable format... Read more
Affected Products : cloudforms- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4412
slim has NULL pointer dereference when using crypt() method from glibc 2.17... Read more
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2013-4411
Review Board: URL processing gives unauthorized users access to review lists... Read more
- Published: Dec. 03, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGH- Published: Dec. 02, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2013-4409
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.... Read more
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2013-4395
Simple Machines Forum (SMF) through 2.0.5 has XSS... Read more
Affected Products : simple_machines_forum- Published: Feb. 12, 2020
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2013-4374
An insecurity temporary file vulnerability exists in RHQ Mongo DB Drift Server through 2013-09-25 when unpacking zipped files.... Read more
- Published: Nov. 04, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-4367
ovirt-engine 3.2 running on Linux kernel 3.1 and newer creates certain files world-writeable due to an upstream kernel change which impacted how python's os.chmod() works when passed a mode of '-1'.... Read more
- Published: Nov. 01, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2013-4364
(1) oo-analytics-export and (2) oo-analytics-import in the openshift-origin-broker-util package in Red Hat OpenShift Enterprise 1 and 2 allow local users to have unspecified impact via a symlink attack on an unspecified file in /tmp.... Read more
- Published: Jan. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2013-4357
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.... Read more
- Published: Dec. 31, 2019
- Modified: Nov. 21, 2024