LiveActive security incident?Get immediate response
CVE archive

March 2013

Browse CVE records published in March 2013, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 550 matching CVEs · Page 4 of 11.

Medium · CVSS 4

CVE-2013-10021: dd32 Debug Bar Plugin class-debug-bar-queries.php render cross site scripting

A vulnerability was found in dd32 Debug Bar Plugin up to 0.8 on WordPress. It has been declared as problematic. Affected by this vulnerability is the function render of the file panels/class-debug-bar-queries.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version 0.8.1 is able to address this issue. The patch is named 0842af8f8a556bc3e39b9ef758173b0a8a9ccbfc. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-222739.

Published Mar 11, 2023 · Updated Aug 6, 2024

Medium · CVSS 4

CVE-2013-10020: MMDeveloper A Forms Plugin a-forms.php cross site scripting

A vulnerability, which was classified as problematic, was found in MMDeveloper A Forms Plugin up to 1.4.2 on WordPress. This affects an unknown part of the file a-forms.php. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. Upgrading to version 1.4.3 is able to address this issue. The identifier of the patch is 3e693197bd69b7173cc16d8d2e0a7d501a2a0b06. It is recommended to upgrade the affected component. The identifier VDB-222609 was assigned to this vulnerability.

Published Mar 10, 2023 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-7462: A directory traversal vulnerability in the web application in McAfee (now Intel Security) SaaS Control Cons...

A directory traversal vulnerability in the web application in McAfee (now Intel Security) SaaS Control Console (SCC) Platform 6.14 before patch 1070, and 6.15 before patch 1076 allows unauthenticated users to view contents of arbitrary system files that did not have file system level read access restrictions via a null-byte injection exploit.

Published Mar 14, 2017 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-7438: Multiple buffer overflows in pbm212030 allow remote attackers to cause a denial of service (crash) or possi...

Multiple buffer overflows in pbm212030 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PBM image, related to (1) stream line data, which triggers a heap-based buffer overflow, or (2) vectors related to an "internal intermediate heap-based buffer."

Published Mar 29, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-7345: The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses m...

The BEGIN regular expression in the awk script detector in magic/Magdir/commands in file before 5.15 uses multiple wildcards with unlimited repetitions, which allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted ASCII file that triggers a large amount of backtracking, as demonstrated via a file with many newline characters.

Published Mar 23, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-7343: Cross-site scripting (XSS) vulnerability in flowplayer.swf in the Flash fallback feature in Flowplayer HTML...

Cross-site scripting (XSS) vulnerability in flowplayer.swf in the Flash fallback feature in Flowplayer HTML5 5.4.3 allows remote attackers to inject arbitrary web script or HTML by using URL encoding within the callback parameter name. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7342.

Published Mar 22, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-7347: Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attackers to ga...

Luci in Red Hat Conga does not properly enforce the user session timeout, which might allow attackers to gain access to the session by reading the __ac session cookie. NOTE: this issue has been SPLIT due to different vulnerability types. Use CVE-2012-3359 for the base64-encoded storage of the user and password in a cookie.

Published Mar 30, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-7341: Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle th...

Multiple cross-site scripting (XSS) vulnerabilities in Flowplayer Flash before 3.2.17, as used in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2, allow remote attackers to inject arbitrary web script or HTML by (1) providing a crafted playerId or (2) referencing an external domain, a related issue to CVE-2013-7342.

Published Mar 22, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-7322: usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid on...

usersfile.c in liboath in OATH Toolkit before 2.4.1 does not properly handle lines containing an invalid one-time-password (OTP) type and a user name in /etc/users.oath, which causes the wrong line to be updated when invalidating an OTP and allows context-dependent attackers to conduct replay attacks, as demonstrated by a commented out line when using libpam-oath.

Published Mar 7, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6938: Unspecified vulnerability in the Service VM in Citrix NetScaler SDX 9.3 before 9.3-64.4 and 10.0 before 10....

Unspecified vulnerability in the Service VM in Citrix NetScaler SDX 9.3 before 9.3-64.4 and 10.0 before 10.0-77.5 and Application Delivery Controller (ADC) 9.3.x before 9.3-64.4, 10.0 before 10.0-77.5, and 10.1 before 10.1-118.7 allows attackers to cause a denial of service via unknown vectors, related to the "Virtual Machine Daemon."

Published Mar 10, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6770: The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly rest...

The CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.3 and 4.4 does not properly restrict the set of users who can execute /system/xbin/su with the --daemon option, which allows attackers to gain privileges by leveraging ADB shell access and a certain Linux UID, and then creating a Trojan horse script.

Published Mar 30, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6774: Untrusted search path vulnerability in the ChainsDD Superuser package 3.1.3 for Android 4.2.x and earlier,...

Untrusted search path vulnerability in the ChainsDD Superuser package 3.1.3 for Android 4.2.x and earlier, CyanogenMod/ClockWorkMod/Koush Superuser package 1.0.2.1 for Android 4.2.x and earlier, and Chainfire SuperSU package before 1.69 for Android 4.2.x and earlier allows attackers to load an arbitrary .jar file and gain privileges via a crafted BOOTCLASSPATH environment variable for a /system/xbin/su process. NOTE: another researcher was unable to reproduce this with ChainsDD Superuser.

Published Mar 30, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6730: IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF2...

IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x before 7.0.0.2 CF27, and 8.0.0.x before 8.0.0.1 CF10, when the wcm.path.traversal.security setting is enabled, allows remote attackers to bypass intended read restrictions on an item by accessing that item within search results.

Published Mar 4, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6720: Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in I...

Directory traversal vulnerability in download.php in the Passive Capture Application (PCA) web console in IBM Tealeaf CX 7.x, 8.x through 8.6, 8.7 before FP2, and 8.8 before FP2 allows remote authenticated users to bypass intended access restrictions via a .. (dot dot) in the log parameter, as demonstrated using a crafted request for a customer-support file, as demonstrated by a log file.

Published Mar 6, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6665: Heap-based buffer overflow in the ResourceProvider::InitializeSoftware function in cc/resources/resource_pr...

Heap-based buffer overflow in the ResourceProvider::InitializeSoftware function in cc/resources/resource_provider.cc in Google Chrome before 33.0.1750.146 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a large texture size that triggers improper memory allocation in the software renderer.

Published Mar 5, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6666: The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google...

The PepperFlashRendererHost::OnNavigate function in renderer/pepper/pepper_flash_renderer_host.cc in Google Chrome before 33.0.1750.146 does not verify that all headers are Cross-Origin Resource Sharing (CORS) simple headers before proceeding with a PPB_Flash.Navigate operation, which might allow remote attackers to bypass intended CORS restrictions via an inappropriate header.

Published Mar 5, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6663: Use-after-free vulnerability in the SVGImage::setContainerSize function in core/svg/graphics/SVGImage.cpp i...

Use-after-free vulnerability in the SVGImage::setContainerSize function in core/svg/graphics/SVGImage.cpp in the SVG implementation in Blink, as used in Google Chrome before 33.0.1750.146, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the resizing of a view.

Published Mar 5, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6664: Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAs...

Use-after-free vulnerability in the FormAssociatedElement::formRemovedFromTree function in core/html/FormAssociatedElement.cpp in Blink, as used in Google Chrome before 33.0.1750.146, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving FORM elements, as demonstrated by use of the speech-recognition feature.

Published Mar 5, 2014 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6501: The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP throug...

The default soap.wsdl_cache_dir setting in (1) php.ini-production and (2) php.ini-development in PHP through 5.6.7 specifies the /tmp directory, which makes it easier for local users to conduct WSDL injection attacks by creating a file under /tmp with a predictable filename that is used by the get_sdl function in ext/soap/php_sdl.c.

Published Mar 30, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-6442: The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 remove...

The owner_set function in smbcacls.c in smbcacls in Samba 4.0.x before 4.0.16 and 4.1.x before 4.1.6 removes an ACL during use of a --chown or --chgrp option, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging an unintended administrative change.

Published Mar 14, 2014 · Updated Aug 6, 2024