Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2013-08-31 CVE-2012-6598 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.8 allows remote authenticated users to execute arbitrary commands via unspecified vectors, aka Ref ID 33080.
network
low complexity
paloaltonetworks CWE-78
critical
9.0
2013-08-31 CVE-2012-6595 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
The device-management command-line interface in Palo Alto Networks PAN-OS 4.0.x before 4.0.9 and 4.1.x before 4.1.2 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34595.
network
low complexity
paloaltonetworks CWE-78
critical
9.0
2013-08-31 CVE-2012-6594 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.11, 4.0.x before 4.0.8, and 4.1.x before 4.1.1 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 34299.
network
low complexity
paloaltonetworks CWE-78
critical
9.0
2013-08-31 CVE-2012-6593 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.4 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 30088.
network
low complexity
paloaltonetworks CWE-78
critical
10.0
2013-08-31 CVE-2012-6592 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote attackers to execute arbitrary commands via unspecified vectors, aka Ref ID 31091.
network
low complexity
paloaltonetworks CWE-78
critical
10.0
2013-08-31 CVE-2012-6591 OS Command Injection vulnerability in Paloaltonetworks Pan-Os
The device-management command-line interface in Palo Alto Networks PAN-OS before 3.1.10 and 4.0.x before 4.0.5 allows remote authenticated administrators to execute arbitrary commands via unspecified vectors, aka Ref ID 31116.
network
low complexity
paloaltonetworks CWE-78
critical
9.0
2013-08-30 CVE-2013-3346 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Adobe Acrobat and Acrobat Reader
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-2013-2719, CVE-2013-2720, CVE-2013-2721, CVE-2013-2722, CVE-2013-2723, CVE-2013-2725, CVE-2013-2726, CVE-2013-2731, CVE-2013-2732, CVE-2013-2734, CVE-2013-2735, CVE-2013-2736, CVE-2013-3337, CVE-2013-3338, CVE-2013-3339, CVE-2013-3340, and CVE-2013-3341.
network
low complexity
adobe CWE-119
critical
10.0
2013-08-29 CVE-2013-3466 Improper Authentication vulnerability in Cisco Secure Access Control Server
The EAP-FAST authentication module in Cisco Secure Access Control Server (ACS) 4.x before 4.2.1.15.11, when a RADIUS server configuration is enabled, does not properly parse user identities, which allows remote attackers to execute arbitrary commands via crafted EAP-FAST packets, aka Bug ID CSCui57636.
network
cisco CWE-287
critical
9.3
2013-08-28 CVE-2013-2782 Cryptographic Issues vulnerability in Schneider-Electric Tburjr900 and Tburjr900 Firmware
Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
network
schneider-electric CWE-310
critical
9.3
2013-08-27 CVE-2013-4974 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Realnetworks Realplayer and Realplayer SP
RealNetworks RealPlayer before 16.0.3.51, and RealPlayer SP 1.0 through 1.1.5, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed RealMedia file.
network
realnetworks CWE-119
critical
9.3