LiveActive security incident?Get immediate response
CVE archive

August 2013

Browse CVE records published in August 2013, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 397 matching CVEs · Page 3 of 8.

Unknown · CVSS Not scored

CVE-2013-0150: Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5...

Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, FirePass 6.0.0 through 6.1.0 and 7.0.0, and other products "when APM is provisioned," allows remote attackers to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.

Published Aug 9, 2013 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2013-2789: The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote a...

The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically proximate attackers to cause a denial of service (master-station infinite loop) via crafted input over a serial line.

Published Aug 22, 2013 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2013-4699: The Yahoo!

The Yahoo! Japan Yafuoku! application 4.3.0 and earlier for iOS and Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

Published Aug 21, 2013 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2013-2796: Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 a...

Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Published Aug 9, 2013 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2013-1190: The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict i...

The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remote attackers to cause a denial of service (Integrated Management Controller reboot or hang) via crafted packets, as demonstrated by nmap, aka Bug ID CSCtx19850.

Published Aug 1, 2013 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2013-2782: Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the sam...

Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.

Published Aug 28, 2013 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2013-7456: gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x...

gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted image that is mishandled by the imagescale function.

Published Aug 7, 2016 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-7422: Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products...

Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.

Published Aug 16, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-7442: GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of (1) CANal1 for the Administrator...

GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of (1) CANal1 for the Administrator user and (2) iis for the IIS user, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires it.

Published Aug 4, 2015 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-7405: The Ad Hoc Reporting feature in GE Healthcare Centricity DMS 4.2 has a password of Never!Mind for the Admin...

The Ad Hoc Reporting feature in GE Healthcare Centricity DMS 4.2 has a password of Never!Mind for the Administrator user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.

Published Aug 4, 2015 · Updated Aug 6, 2024