Vulnerabilities (CVE)

Filtered by CWE-20
Total 10130 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-7483 1 Hbwsl 1 Slidedeck 2 2024-11-21 7.5 HIGH 9.8 CRITICAL
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
CVE-2013-7333 1 Projectfloodlight 1 Open Sdn Controller 2024-11-21 7.8 HIGH 7.5 HIGH
A vulnerability in version 0.90 of the Open Floodlight SDN controller software could allow an attacker with access to the OpenFlow control network to selectively disconnect individual switches from the SDN controller, causing degradation and eventually denial of network access to all devices connected to the targeted switch.
CVE-2013-7172 1 Slackware 1 Slackware Linux 2024-11-21 7.2 HIGH 7.8 HIGH
Slackware 13.1, 13.37, 14.0 and 14.1 contain world-writable permissions on the iodbctest and iodbctestw programs within the libiodbc package, which could allow local users to use RPATH information to execute arbitrary code with root privileges.
CVE-2013-7171 1 Slackware 1 Slackware Linux 2024-11-21 10.0 HIGH 9.8 CRITICAL
Slackware 14.0 and 14.1, and Slackware LLVM 3.0-i486-2 and 3.3-i486-2, contain world-writable permissions on the /tmp directory which could allow remote attackers to execute arbitrary code with root privileges.
CVE-2013-5106 1 Python-mode Project 1 Python-mode 2024-11-21 6.8 MEDIUM 8.8 HIGH
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
CVE-2013-4751 3 Fedoraproject, Redhat, Sensiolabs 3 Fedora, Enterprise Linux, Symfony 2024-11-21 4.9 MEDIUM 8.1 HIGH
php-symfony2-Validator has loss of information during serialization
CVE-2013-4535 2 Qemu, Redhat 6 Qemu, Enterprise Linux Desktop, Enterprise Linux Server and 3 more 2024-11-21 7.2 HIGH 8.8 HIGH
The virtqueue_map_sg function in hw/virtio/virtio.c in QEMU before 1.7.2 allows remote attackers to execute arbitrary files via a crafted savevm image, related to virtio-block or virtio-serial read.
CVE-2013-4409 3 Fedoraproject, Redhat, Reviewboard 4 Fedora, Enterprise Linux, Djblets and 1 more 2024-11-21 7.5 HIGH 9.8 CRITICAL
An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
CVE-2013-4245 2 Debian, Gnome 2 Debian Linux, Orca 2024-11-21 4.4 MEDIUM 7.3 HIGH
Orca has arbitrary code execution due to insecure Python module load
CVE-2013-4103 1 Cryptocat Project 1 Cryptocat 2024-11-21 7.5 HIGH 9.8 CRITICAL
Cryptocat before 2.0.22 has Remote Script Injection due to improperly sanitizing user input
CVE-2013-4101 1 Cryptocat Project 1 Cryptocat 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
Cryptocat before 2.0.22 Link Markup Decorator HTML Handling Weakness
CVE-2013-4100 1 Cryptocat Project 1 Cryptocat 2024-11-21 5.0 MEDIUM 7.5 HIGH
Cryptocat before 2.0.22 has Remote Denial of Service via username
CVE-2013-3945 1 Extensis 1 Mrsid 2024-11-21 6.8 MEDIUM 7.8 HIGH
The MrSID plugin (MrSID.dll) before 4.37 for IrfanView allows remote attackers to execute arbitrary code via a nband tag.
CVE-2013-3738 1 Zabbix 1 Zabbix 2024-11-21 7.5 HIGH 9.8 CRITICAL
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
CVE-2013-3718 4 Debian, Gnome, Opensuse and 1 more 4 Debian Linux, Evince, Opensuse and 1 more 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
evince is missing a check on number of pages which can lead to a segmentation fault
CVE-2013-2571 1 Hcomm 1 Xpient Iris 2024-11-21 7.5 HIGH 9.8 CRITICAL
Iris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a crafted request to TCP port 7510, as demonstrated by opening the cash drawer.
CVE-2013-2259 1 Cryptocat Project 1 Cryptocat 2024-11-21 7.5 HIGH 9.8 CRITICAL
Cryptocat before 2.0.22 has Arbitrary Code Execution on Firefox Conversation Overview
CVE-2013-2227 2 Debian, Glpi-project 2 Debian Linux, Glpi 2024-11-21 5.0 MEDIUM 7.5 HIGH
GLPI 0.83.7 has Local File Inclusion in common.tabs.php.
CVE-2013-2103 1 Redhat 1 Openshift 2024-11-21 5.5 MEDIUM 8.1 HIGH
OpenShift cartridge allows remote URL retrieval
CVE-2013-2093 1 Dolibarr 1 Dolibarr Erp\/crm 2024-11-21 10.0 HIGH 9.8 CRITICAL
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.