LiveActive security incident?Get immediate response
CVE archive

September 2013

Browse CVE records published in September 2013, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 450 matching CVEs · Page 6 of 9.

Unknown · CVSS Not scored

CVE-2013-4314: The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in...

The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority.

Published Sep 30, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4278: The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enfo...

The "create an instance" API in OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not properly enforce the os-flavor-access:is_public property, which allows remote authenticated users to boot arbitrary flavors by guessing the flavor id. NOTE: this issue is due to an incomplete fix for CVE-2013-2256.

Published Sep 16, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4325: The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 do...

The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process.

Published Sep 23, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4202: The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenSt...

The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity Expansion (XEE) attack. NOTE: this issue is due to an incomplete fix for CVE-2013-1664.

Published Sep 16, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4307: Multiple cross-site scripting (XSS) vulnerabilities in repo/includes/EntityView.php in the Wikibase extensi...

Multiple cross-site scripting (XSS) vulnerabilities in repo/includes/EntityView.php in the Wikibase extension for MediaWiki 1.19.x before 1.19.8, 1.20.x before 1.20.7, and 1.21.x before 1.21.2 allow (1) remote attackers to inject arbitrary web script or HTML via a label in the "In other languages" section or (2) remote administrators to inject arbitrary web script or HTML via a description.

Published Sep 11, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4181: Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in oVirt E...

Cross-site scripting (XSS) vulnerability in the addAlert function in the RedirectServlet servlet in oVirt Engine and Red Hat Enterprise Virtualization Manager (RHEV-M), as used in Red Hat Enterprise Virtualization 3 and 3.2, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Published Sep 16, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4132: KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_e...

KDE-Workspace 4.10.5 and earlier does not properly handle the return value of the glibc 2.17 crypt and pw_encrypt functions, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via (1) an invalid salt or a (2) DES or (3) MD5 encrypted password, when FIPS-140 is enable, to KDM or an (4) invalid password to KCheckPass.

Published Sep 16, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4053: The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7....

The WS-Security implementation in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.31, 8.0 before 8.0.0.8, and 8.5 before 8.5.5.1, and WAS Feature Pack for Web Services 6.1 before 6.1.0.47, when a trust store is configured for XML Digital Signatures, does not properly verify X.509 certificates, which allows remote attackers to obtain privileged access via unspecified vectors.

Published Sep 20, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4025: IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Conf...

IBM Data Studio Web Console 3.x before 3.2, Optim Performance Manager 5.x before 5.2, InfoSphere Optim Configuration Manager 2.x before 2.2, and DB2 Recovery Expert 2.x do not have an off autocomplete attribute for the login-password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.

Published Sep 25, 2013 · Updated Aug 6, 2024