LiveActive security incident?Get immediate response
CVE archive

November 2013

Browse CVE records published in November 2013, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 505 matching CVEs · Page 8 of 11.

Unknown · CVSS Not scored

CVE-2013-4275: Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6....

Cross-site scripting (XSS) vulnerability in the zen_breadcrumb function in template.php in the Zen theme 6.x-1.x, 7.x-3.x before 7.x-3.2, and 7.x-5.x before 7.x-5.4 for Drupal allows remote authenticated users with the "administer themes" permission to inject arbitrary web script or HTML via the breadcrumb separator field.

Published Nov 13, 2019 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4164: Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 prev...

Heap-based buffer overflow in Ruby 1.8, 1.9 before 1.9.3-p484, 2.0 before 2.0.0-p353, 2.1 before 2.1.0 preview2, and trunk before revision 43780 allows context-dependent attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a string that is converted to a floating point value, as demonstrated using (1) the to_f method or (2) JSON.parse.

Published Nov 23, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4034: IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4,...

IBM Cognos Business Intelligence 8.4.1 before IF3, 10.1.0 before IF4, 10.1.1 before IF4, 10.2.0 before IF4, 10.2.1 before IF2, and 10.2.1.1 before IF1 allows remote authenticated users to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

Published Nov 16, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-4036: Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Inform...

Cross-site scripting (XSS) vulnerability in IBM InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 FP13, and IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 FP7 and 11.0 before FP2, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Published Nov 27, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-3940: Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server...

Integer overflow in the Graphics Device Interface (GDI) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted image in a Windows Write (.wri) document, which is not properly handled in WordPad, aka "Graphics Device Interface Integer Overflow Vulnerability."

Published Nov 13, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-3905: Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained...

Microsoft Outlook 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT does not properly expand metadata contained in S/MIME certificates, which allows remote attackers to obtain sensitive network configuration and state information via a crafted certificate in an e-mail message, aka "S/MIME AIA Vulnerability."

Published Nov 13, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-3898: Microsoft Windows 8 and Windows Server 2012, when Hyper-V is used, does not ensure memory-address validity,...

Microsoft Windows 8 and Windows Server 2012, when Hyper-V is used, does not ensure memory-address validity, which allows guest OS users to execute arbitrary code in all guest OS instances, and allows guest OS users to cause a denial of service (host OS crash), via a guest-to-host hypercall with a crafted function parameter, aka "Address Corruption Vulnerability."

Published Nov 13, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-3908: Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Origin Po...

Microsoft Internet Explorer 6 through 10 allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information from any visited document via a crafted web page that is not properly handled during a print-preview action, aka "Internet Explorer Information Disclosure Vulnerability."

Published Nov 13, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-3887: The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Wind...

The Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 allows local users to obtain sensitive information from kernel memory by leveraging improper copy operations, aka "Ancillary Function Driver Information Disclosure Vulnerability."

Published Nov 13, 2013 · Updated Aug 6, 2024