Total
5442 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-5975 | 1 F5 | 1 Big-ip Access Policy Manager | 2013-10-31 | 4.3 MEDIUM | N/A |
The access policy logon page (logon.inc) in F5 BIG-IP APM 11.1.0 through 11.2.1 allows remote attackers to conduct clickjacking attacks via unspecified vectors. | |||||
CVE-2013-5145 | 1 Apple | 1 Iphone Os | 2013-10-31 | 6.3 MEDIUM | N/A |
kextd in Kext Management in Apple iOS before 7 does not properly verify authorization for IPC messages, which allows local users to (1) load or (2) unload kernel extensions via a crafted message. | |||||
CVE-2012-4572 | 1 Redhat | 2 Jboss Enterprise Application Platform, Jboss Enterprise Portal Platform | 2013-10-30 | 3.7 LOW | N/A |
Red Hat JBoss Enterprise Application Platform (EAP) before 6.1.0 and JBoss Portal before 6.1.0 does not load the implementation of a custom authorization module for a new application when an implementation is already loaded and the modules share class names, which allows local users to control certain applications' authorization decisions via a crafted application. | |||||
CVE-2012-0827 | 1 Drupal | 1 Drupal | 2013-10-29 | 3.5 LOW | N/A |
The File module in Drupal 7.x before 7.11, when using unspecified field access modules, allows remote authenticated users to read arbitrary private files that are associated with restricted fields via unspecified vectors. | |||||
CVE-2013-1067 | 1 Canonical | 1 Ubuntu Linux | 2013-10-28 | 4.9 MEDIUM | N/A |
Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by reading the file. | |||||
CVE-2013-6128 | 1 Wellintech | 1 Kingview | 2013-10-28 | 5.8 MEDIUM | N/A |
The KCHARTXYLib.KChartXY ActiveX control in KChartXY.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict SaveToFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the single pathname argument, as demonstrated by a directory traversal attack. | |||||
CVE-2013-3280 | 1 Emc | 1 Rsa Authentication Agent | 2013-10-25 | 7.5 HIGH | N/A |
EMC RSA Authentication Agent 7.1.x before 7.1.2 for Web for Internet Information Services has a fail-open design, which allows remote attackers to bypass intended access restrictions via vectors that trigger an agent crash. | |||||
CVE-2013-5521 | 1 Cisco | 1 Identity Services Engine Software | 2013-10-25 | 5.0 MEDIUM | N/A |
Cisco Identity Services Engine does not properly restrict the creation of guest accounts, which allows remote attackers to cause a denial of service (exhaustion of the account supply) via a series of requests within one session, aka Bug ID CSCue94287. | |||||
CVE-2013-5522 | 1 Cisco | 2 Catalyst 3750-x, Ios | 2013-10-25 | 6.8 MEDIUM | N/A |
Cisco IOS on Catalyst 3750X switches has default Service Module credentials, which makes it easier for local users to gain privileges via a Service Module login, aka Bug ID CSCue92286. | |||||
CVE-2013-5154 | 1 Apple | 1 Iphone Os | 2013-10-25 | 4.3 MEDIUM | N/A |
The Sandbox subsystem in Apple iOS before 7 determines the sandboxing requirement for a #! application on the basis of the script interpreter instead of the script, which allows attackers to bypass intended access restrictions via a crafted application. | |||||
CVE-2013-5149 | 1 Apple | 1 Iphone Os | 2013-10-25 | 4.3 MEDIUM | N/A |
The Push Notifications subsystem in Apple iOS before 7 provides the push-notification token to an app without user approval, which allows attackers to obtain sensitive information via an app that employs a crafted push-notification registration process. | |||||
CVE-2013-5165 | 1 Apple | 1 Mac Os X | 2013-10-25 | 6.4 MEDIUM | N/A |
socketfilterfw in Application Firewall in Apple Mac OS X before 10.9 does not properly implement the --blockApp option, which allows remote attackers to bypass intended access restrictions via a network connection to an application for which blocking was configured. | |||||
CVE-2013-5169 | 1 Apple | 1 Mac Os X | 2013-10-25 | 1.9 LOW | N/A |
CoreGraphics in Apple Mac OS X before 10.9, when display-sleep mode is used, does not ensure that screen locking blocks the visibility of all windows, which allows physically proximate attackers to obtain sensitive information by reading the screen. | |||||
CVE-2013-5186 | 1 Apple | 1 Mac Os X | 2013-10-24 | 2.1 LOW | N/A |
Power Management in Apple Mac OS X before 10.9 does not properly handle the interaction between locking and power assertions, which allows physically proximate attackers to obtain sensitive information by reading a screen that should have transitioned into the locked state. | |||||
CVE-2013-5189 | 1 Apple | 1 Mac Os X | 2013-10-24 | 5.8 MEDIUM | N/A |
Apple Mac OS X before 10.9 does not preserve a certain administrative system-preferences setting across software updates, which allows context-dependent attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended security configuration after the completion of an update. | |||||
CVE-2013-5148 | 1 Apple | 1 Keynote | 2013-10-24 | 7.2 HIGH | N/A |
Apple Keynote before 6.0 does not properly handle the interaction between Keynote presentation mode and the Screen Lock implementation, which allows physically proximate attackers to obtain access by visiting an unattended workstation on which this mode was enabled during a sleep operation. | |||||
CVE-2013-5190 | 1 Apple | 1 Mac Os X | 2013-10-24 | 4.3 MEDIUM | N/A |
Smart Card Services in Apple Mac OS X before 10.9 does not properly implement certificate-revocation checks, which allows remote attackers to cause a denial of service (Smart Card usage outage) by interfering with the revocation-check procedure. | |||||
CVE-2013-6246 | 1 Dell | 1 Quest One Password Manager | 2013-10-24 | 5.0 MEDIUM | N/A |
The Dell Quest One Password Manager, possibly 5.0, allows remote attackers to bypass CAPTCHA protections and obtain sensitive information (user's full name) by sending a login request with a valid domain and username but without the CaptchaType, UseCaptchaEveryTime, and CaptchaResponse parameters. | |||||
CVE-2013-5191 | 1 Apple | 1 Mac Os X | 2013-10-24 | 2.1 LOW | N/A |
The syslog implementation in Apple Mac OS X before 10.9 allows local users to obtain sensitive information by leveraging access to the Guest account and reading console-log messages from previous Guest sessions. | |||||
CVE-2013-5188 | 1 Apple | 1 Mac Os X | 2013-10-24 | 4.0 MEDIUM | N/A |
The Screen Lock implementation in Apple Mac OS X before 10.9, when hibernation and autologin are enabled, does not require a password for a transition out of hibernation, which allows physically proximate attackers to obtain access by visiting an unattended workstation in the hibernating state. |