Vulnerabilities (CVE)

Total 395540 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2013-5668 1 Thecus 2 N8800 Nas Server, N8800 Nas Server Firmware 2026-06-16 7.8 HIGH N/A
The ADS/NT Support page on the Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to discover the administrator credentials by reading this page's cleartext content.
CVE-2013-5667 1 Thecus 2 N8800 Nas Server, N8800 Nas Server Firmware 2026-06-16 10.0 HIGH N/A
The Thecus NAS server N8800 with firmware 5.03.01 allows remote attackers to execute arbitrary commands via a get_userid action with shell metacharacters in the username parameter.
CVE-2013-5666 1 Freebsd 1 Freebsd 2026-06-16 4.7 MEDIUM N/A
The sendfile system-call implementation in sys/kern/uipc_syscalls.c in the kernel in FreeBSD 9.2-RC1 and 9.2-RC2 does not properly pad transmissions, which allows local users to obtain sensitive information (kernel memory) via a length greater than the length of the file.
CVE-2013-5664 1 Paloaltonetworks 1 Pan-os 2026-06-16 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908.
CVE-2013-5663 1 Paloaltonetworks 1 Pan-os 2026-06-16 4.3 MEDIUM N/A
The App-ID cache feature in Palo Alto Networks PAN-OS before 4.0.14, 4.1.x before 4.1.11, and 5.0.x before 5.0.2 allows remote attackers to bypass intended security policies via crafted requests that trigger invalid caching, as demonstrated by incorrect identification of HTTP traffic as SIP traffic, aka Ref ID 47195.
CVE-2013-5661 4 Isc, Nic, Nlnetlabs and 1 more 4 Bind, Knot Resolver, Nsd and 1 more 2026-06-16 2.6 LOW 5.9 MEDIUM
Cache Poisoning issue exists in DNS Response Rate Limiting.
CVE-2013-5660 1 Powersoftware 1 Winarchiver 2026-06-16 9.3 HIGH N/A
Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.
CVE-2013-5659 1 Info-zip 1 Wiz 2026-06-16 5.0 MEDIUM 7.5 HIGH
Wiz 5.0.3 has a user mode write access violation
CVE-2013-5658 1 Aultware 1 Pwstore 2026-06-16 4.3 MEDIUM 6.1 MEDIUM
AultWare pwStore 2010.8.30.0 has XSS
CVE-2013-5657 1 Aultware 1 Pwstore 2026-06-16 5.0 MEDIUM 7.5 HIGH
AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request
CVE-2013-5656 1 Fuzezip Project 1 Fuzezip 2026-06-16 4.6 MEDIUM 7.8 HIGH
FuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerability
CVE-2013-5655 1 Xiaowen Huang 1 Yingzhi Python Programming Language 2026-06-16 6.4 MEDIUM N/A
Directory traversal vulnerability in the FTP server in YingZhi Python Programming Language for iOS 1.9 allows remote attackers to read and possibly write arbitrary files via a .. (dot dot) in the default URI.
CVE-2013-5654 1 Yingzhipython Project 1 Yingzhipython 2026-06-16 9.4 HIGH 9.1 CRITICAL
Vulnerability in YingZhi Python Programming Language v1.9 allows arbitrary anonymous uploads to the phone's storage
CVE-2013-5653 2 Artifex, Debian 2 Afpl Ghostscript, Debian Linux 2026-06-16 4.3 MEDIUM 5.5 MEDIUM
The getenv and filenameforall functions in Ghostscript 9.10 ignore the "-dSAFER" argument, which allows remote attackers to read data via a crafted postscript file.
CVE-2013-5651 1 Redhat 1 Libvirt 2026-06-16 5.0 MEDIUM N/A
The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a crafted bitmap, as demonstrated by a large nodeset value to numatune.
CVE-2013-5650 1 Juniper 2 Junos Pulse Access Control Service, Junos Pulse Secure Access Service 2026-06-16 5.4 MEDIUM N/A
Junos Pulse Secure Access Service (IVE) 7.1 before 7.1r5, 7.2 before 7.2r10, 7.3 before 7.3r6, and 7.4 before 7.4r3 and Junos Pulse Access Control Service (UAC) 4.1 before 4.1r8.1, 4.2 before 4.2r5, 4.3 before 4.3r6 and 4.4 before 4.4r3, when a hardware SSL acceleration card is enabled, allows remote attackers to cause a denial of service (device hang) via a crafted packet.
CVE-2013-5649 1 Juniper 1 Ive Os 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.1 before 7.1r15, 7.2 before 7.2r11, 7.3 before 7.3r6, and 7.4 before 7.4r3 allow (1) remote attackers to inject arbitrary web script or HTML via vectors involving login pages, and allow (2) remote authenticated users to inject arbitrary web script or HTML via vectors involving a support page.
CVE-2013-5648 1 Id 2 Id-software, Libdigidoc 2026-06-16 6.8 MEDIUM N/A
Absolute path traversal vulnerability in the handleStartDataFile function in DigiDocSAXParser.c in libdigidoc 3.6.0.0, as used in ID-software before 3.7.2 and other products, allows remote attackers to overwrite arbitrary files via a filename beginning with / (slash) or \ (backslash) in a DDOC file.
CVE-2013-5647 2 Adam Zaninovich, Ruby-lang 2 Sounder, Ruby 2026-06-16 7.5 HIGH N/A
lib/sounder/sound.rb in the sounder gem 1.0.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
CVE-2013-5646 1 Roundcube 1 Webmail 2026-06-16 3.5 LOW N/A
Cross-site scripting (XSS) vulnerability in Roundcube webmail 1.0-git allows remote authenticated users to inject arbitrary web script or HTML via the Name field of an addressbook group.