Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2013-10-01 CVE-2013-3539 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.
6.8
2013-10-01 CVE-2013-5745 Improper Input Validation vulnerability in multiple products
The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service (infinite loop, CPU and disk consumption) via multiple crafted requests during authentication.
7.1
2013-10-01 CVE-2013-4708 Cryptographic Issues vulnerability in IIJ products
The PPP Access Concentrator (PPPAC) in Internet Initiative Japan Inc.
network
high complexity
iij CWE-310
4.0
2013-10-01 CVE-2013-4361 Information Exposure vulnerability in XEN
The fbld instruction emulation in Xen 3.3.x through 4.3.x does not use the correct variable for the source effective address, which allows local HVM guests to obtain hypervisor stack information by reading the values used by the instruction.
local
low complexity
xen CWE-200
2.1
2013-10-01 CVE-2013-4210 Remote Denial of Service vulnerability in Red Hat JBoss Remoting
The org.jboss.remoting.transport.socket.ServerThread class in Red Hat JBoss Remoting for Red Hat JBoss SOA Platform 5.3.1 GA, Web Platform 5.2.0, Enterprise Application Platform 5.2.0, and other products allows remote attackers to cause a denial of service (file descriptor consumption) via unspecified vectors.
network
low complexity
redhat
5.0
2013-10-01 CVE-2013-2269 Permissions, Privileges, and Access Controls vulnerability in Arubanetworks Clearpass and Clearpass Guest
The Sponsorship Confirmation functionality in Aruba Networks ClearPass 5.x, 6.0.1, and 6.0.2, and Amigopod/ClearPass Guest 3.0 through 3.9.7, allows remote attackers to bypass intended access restrictions and approve a request by sending a guest request, then using "parameter manipulation" in conjunction with information from a "default holding page" to discover the link that is used for sponsor approval of the guest request, then performing a direct request to that link.
network
low complexity
arubanetworks CWE-264
5.0
2013-10-01 CVE-2012-5627 Insufficiently Protected Credentials vulnerability in multiple products
Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.
network
low complexity
oracle mariadb CWE-522
4.0
2013-10-01 CVE-2012-2126 Cryptographic Issues vulnerability in Rubygems
RubyGems before 1.8.23 does not verify an SSL certificate, which allows remote attackers to modify a gem during installation via a man-in-the-middle attack.
4.3
2013-10-01 CVE-2012-2125 URI Redirection vulnerability in RubyGems
RubyGems before 1.8.23 can redirect HTTPS connections to HTTP, which makes it easier for remote attackers to observe or modify a gem during installation via a man-in-the-middle attack.
5.8
2013-10-01 CVE-2013-5395 Unspecified vulnerability in IBM Maximo Asset Management
IBM Maximo Asset Management 6.2 through 6.2.8, 7.1 before 7.1.1.12, and 7.5 before 7.5.0.5 allows remote attackers to bypass intended access restrictions via unspecified vectors.
network
low complexity
ibm
7.5