Total
3668 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2013-1966 | 1 Apache | 1 Struts | 2024-02-28 | 9.3 HIGH | N/A |
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. | |||||
CVE-2013-3651 | 1 Lockon | 1 Ec-cube | 2024-02-28 | 7.5 HIGH | N/A |
LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and data/class/SC_FormParam.php. | |||||
CVE-2013-2617 | 1 Curl Project | 1 Curl | 2024-02-28 | 7.5 HIGH | N/A |
lib/curl.rb in the Curl Gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |||||
CVE-2013-0912 | 1 Google | 1 Chrome | 2024-02-28 | 7.5 HIGH | N/A |
WebKit in Google Chrome before 25.0.1364.160 allows remote attackers to execute arbitrary code via vectors that leverage "type confusion." | |||||
CVE-2013-3631 | 1 Nas4free | 1 Nas4free | 2024-02-28 | 6.0 MEDIUM | N/A |
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execute Command" feature. NOTE: this issue might not be a vulnerability, since it appears to be part of legitimate, intentionally-exposed functionality by the developer and is allowed within the intended security policy. | |||||
CVE-2013-6795 | 1 Rackspace | 1 Openstack Windows Guest Agent | 2024-02-28 | 9.3 HIGH | N/A |
The Updater in Rackspace Openstack Windows Guest Agent for XenServer before 1.2.6.0 allows remote attackers to execute arbitrary code via a crafted serialized .NET object to TCP port 1984, which triggers the download and extraction of a ZIP file that overwrites the Agent service binary. | |||||
CVE-2013-3134 | 1 Microsoft | 1 .net Framework | 2024-02-28 | 9.3 HIGH | N/A |
The Common Language Runtime (CLR) in Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 on 64-bit platforms does not properly allocate arrays of structures, which allows remote attackers to execute arbitrary code via a crafted .NET Framework application that changes array data, aka "Array Allocation Vulnerability." | |||||
CVE-2013-4479 | 1 Supmua | 1 Sup | 2024-02-28 | 6.8 MEDIUM | N/A |
lib/sup/message_chunks.rb in Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the content_type of an email attachment. | |||||
CVE-2013-1762 | 1 Stunnel | 1 Stunnel | 2024-02-28 | 6.6 MEDIUM | N/A |
stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow. | |||||
CVE-2013-3520 | 1 Vmware | 1 Vcenter Chargeback Manager | 2024-02-28 | 7.5 HIGH | N/A |
VMware vCenter Chargeback Manager (aka CBM) before 2.5.1 does not proper handle uploads, which allows remote attackers to execute arbitrary code via unspecified vectors. | |||||
CVE-2013-4203 | 1 Richard Cook | 1 Rgpg | 2024-02-28 | 7.5 HIGH | N/A |
The self.run_gpg function in lib/rgpg/gpg_helper.rb in the rgpg gem before 0.2.3 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in unspecified vectors. | |||||
CVE-2013-1637 | 1 Opera | 1 Opera Browser | 2024-02-28 | 9.3 HIGH | N/A |
Opera before 12.13 allows remote attackers to execute arbitrary code via vectors involving DOM events. | |||||
CVE-2013-1777 | 2 Apache, Ibm | 2 Geronimo, Websphere Application Server | 2024-02-28 | 10.0 HIGH | N/A |
The JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and other products, does not properly implement the RMI classloader, which allows remote attackers to execute arbitrary code by using the JMX connector to send a crafted serialized object. | |||||
CVE-2013-2802 | 1 Sixnet | 2 Rtu Firmware, Udr | 2024-02-28 | 10.0 HIGH | N/A |
The universal protocol implementation in Sixnet UDR before 2.0 and RTU firmware before 4.8 allows remote attackers to execute arbitrary code; read, modify, or create files; or obtain file metadata via function opcodes. | |||||
CVE-2013-3131 | 1 Microsoft | 2 .net Framework, Silverlight | 2024-02-28 | 9.3 HIGH | N/A |
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5, and Silverlight 5 before 5.1.20513.0, does not properly prevent changes to data in multidimensional arrays of structures, which allows remote attackers to execute arbitrary code via (1) a crafted .NET Framework application or (2) a crafted Silverlight application, aka "Array Access Violation Vulnerability." | |||||
CVE-2013-1898 | 1 Digineo | 1 Thumbshooter | 2024-02-28 | 7.5 HIGH | N/A |
lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |||||
CVE-2013-6671 | 6 Canonical, Fedoraproject, Mozilla and 3 more | 17 Ubuntu Linux, Fedora, Firefox and 14 more | 2024-02-28 | 10.0 HIGH | 9.8 CRITICAL |
The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code via crafted use of JavaScript code for ordered list elements. | |||||
CVE-2013-4957 | 1 Puppet | 1 Puppet Enterprise | 2024-02-28 | 6.8 MEDIUM | N/A |
The dashboard report in Puppet Enterprise before 3.0.1 allows attackers to execute arbitrary YAML code via a crafted report-specific type. | |||||
CVE-2013-2615 | 1 Rubygems | 1 Fastreader | 2024-02-28 | 7.5 HIGH | N/A |
lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL. | |||||
CVE-2013-3133 | 1 Microsoft | 1 .net Framework | 2024-02-28 | 9.3 HIGH | N/A |
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4, and 4.5 does not properly check the permissions of objects that use reflection, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (XBAP) or (2) a crafted .NET Framework application, aka "Anonymous Method Injection Vulnerability." |