CVE-2013-1330
published 2013-09-11CVE-2013-1330: The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 does not…
PriorityP263critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
27.41%
97.8th percentile
The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 does not set the EnableViewStateMac attribute, which allows remote attackers to execute arbitrary code by leveraging an unassigned workflow, aka "MAC Disabled Vulnerability."
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | office_web_apps | — | — |
| microsoft | sharepoint_foundation | — | — |
| microsoft | sharepoint_portal_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_server | — | — |
| microsoft | sharepoint_services | — | — |
| microsoft | sharepoint_services | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hcc7-7rjj-r32g: The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 do
ghsa_unreviewed·2022-05-14
CVE-2013-1330 [HIGH] CWE-20 GHSA-hcc7-7rjj-r32g: The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 do
The default configuration of Microsoft SharePoint Portal Server 2003 SP3, SharePoint Server 2007 SP3 and 2010 SP1 and SP2, and Office Web Apps 2010 does not set the EnableViewStateMac attribute, which allows remote attackers to execute arbitrary code by leveraging an unassigned workflow, aka "MAC Disabled Vulnerability."
Red Hat
mysql: unspecified DoS related to Server Optimizer (CPU July 2013)
vendor_redhat·2013-07-17·CVSS 4.0
CVE-2013-3804 [MEDIUM] mysql: unspecified DoS related to Server Optimizer (CPU July 2013)
mysql: unspecified DoS related to Server Optimizer (CPU July 2013)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer.
Statement: This issue was addressed in the package mysql55-mysql as shipped with Red Hat Enterprise Linux 5 via RHEA-2013:1330. This issue was addressed in the package mysql as shipped with Red Hat Enterprise Linux 6 via RHBA-2013:1647.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Package: mysql51-mysql (Red Hat Enterprise Linux 5) - Affected
Red Hat
mysql: unspecified DoS related to Full Text Search (CPU July 2013)
vendor_redhat·2013-07-17·CVSS 4.0
CVE-2013-3802 [MEDIUM] mysql: unspecified DoS related to Full Text Search (CPU July 2013)
mysql: unspecified DoS related to Full Text Search (CPU July 2013)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related to Full Text Search.
Statement: This issue was addressed in the package mysql55-mysql as shipped with Red Hat Enterprise Linux 5 via RHEA-2013:1330. This issue was addressed in the package mysql as shipped with Red Hat Enterprise Linux 6 via RHBA-2013:1647.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Package: mysql51-mysql (Red Hat Enterprise Linux 5) - Affected
Red Hat
mysql: unspecified DoS related to Server Options (CPU July 2013)
vendor_redhat·2013-07-17·CVSS 4.0
CVE-2013-3808 [MEDIUM] mysql: unspecified DoS related to Server Options (CPU July 2013)
mysql: unspecified DoS related to Server Options (CPU July 2013)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
Statement: This issue was addressed in the package mysql55-mysql as shipped with Red Hat Enterprise Linux 5 via RHEA-2013:1330. This issue was addressed in the package mysql as shipped with Red Hat Enterprise Linux 6 via RHSA-2013:0772.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
mysql: unspecified vulnerability related to Information Schema (CPU April 2013)
vendor_redhat·2013-04-16·CVSS 6.5
CVE-2013-2378 [MEDIUM] mysql: unspecified vulnerability related to Information Schema (CPU April 2013)
mysql: unspecified vulnerability related to Information Schema (CPU April 2013)
Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, 5.5.29 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Information Schema.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
mysql: unspecified vulnerability related to Server Privileges (CPU April 2013)
vendor_redhat·2013-04-16·CVSS 6.5
CVE-2013-1531 [MEDIUM] mysql: unspecified vulnerability related to Server Privileges (CPU April 2013)
mysql: unspecified vulnerability related to Server Privileges (CPU April 2013)
Unspecified vulnerability in Oracle MySQL 5.1.66 and earlier and 5.5.28 and earlier allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Server Privileges.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
mysql: unspecified DoS related to Server Locking (CPU April 2013)
vendor_redhat·2013-04-16·CVSS 2.8
CVE-2013-1506 [LOW] mysql: unspecified DoS related to Server Locking (CPU April 2013)
mysql: unspecified DoS related to Server Locking (CPU April 2013)
Unspecified vulnerability in Oracle MySQL 5.1.67 and earlier, 5.5.29 and earlier, and 5.6.10 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server Locking.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
mysql: unspecified vulnerability related to Server Install (CPU April 2013)
vendor_redhat·2013-04-16·CVSS 3.0
CVE-2013-2391 [LOW] mysql: unspecified vulnerability related to Server Install (CPU April 2013)
mysql: unspecified vulnerability related to Server Install (CPU April 2013)
Unspecified vulnerability in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 and earlier allows local users to affect confidentiality and integrity via unknown vectors related to Server Install.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
mysql: geometry query crashes mysqld (CPU July 2013)
vendor_redhat·2013-03-05·CVSS 5.0
CVE-2013-1861 [MEDIUM] mysql: geometry query crashes mysqld (CPU July 2013)
mysql: geometry query crashes mysqld (CPU July 2013)
MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted geometry feature that specifies a large number of points, which is not properly handled when processing the binary representation of this feature, related to a numeric calculation error.
Statement: This issue was addressed in the package mysql55-mysql as shipped with Red Hat Enterprise Linux 5 via RHEA-2013:1330. This issue was addressed in the package mysql as shipped with Red Hat Enterprise Linux 6 via RHBA-2013:1647.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Pa
Red Hat
mysql: unspecified DoS vulnerability related to Server Full Text Search (CPU Oct 2012)
vendor_redhat·2012-10-16·CVSS 3.5
CVE-2012-3167 [LOW] mysql: unspecified DoS vulnerability related to Server Full Text Search (CPU Oct 2012)
mysql: unspecified DoS vulnerability related to Server Full Text Search (CPU Oct 2012)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Full Text Search.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
mysql: unspecified DoS vulnerability in MyISAM (Oracle CPU April 2012)
vendor_redhat·2012-04-17·CVSS 4.0
CVE-2012-0583 [MEDIUM] mysql: unspecified DoS vulnerability in MyISAM (Oracle CPU April 2012)
mysql: unspecified DoS vulnerability in MyISAM (Oracle CPU April 2012)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.60 and earlier, and 5.5.19 and earlier, allows remote authenticated users to affect availability, related to MyISAM.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
Red Hat
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
vendor_redhat·2012-04-17·CVSS 4.0
CVE-2012-1703 [MEDIUM] mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
mysql: unspecified DoS vulnerability related to Server Optimizer (CPU Apr 2012)
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.61 and earlier, and 5.5.21 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server Optimizer, a different vulnerability than CVE-2012-1690.
Statement: On Red Hat Enterprise Linux 5.10, new MySQL 5.5 packages are available which are not vulnerable to this issue. Future updates for MySQL 5.0 will no longer be made available (mysql-5.0.* and related packages); security advisories will be provided only for MySQL 5.5. Please refer to https://rhn.redhat.com/errata/RHEA-2013-1330.html for further information.
Package: mysql (Red Hat Enterprise Linux 5) - Under investigation
No detection rules found.
No public exploits indexed.
Talos
Microsoft Update Tuesday: December 2013, some 0-day fixes
blogs_talos·2013-12-10·CVSS 5.5
CVE-2013-5045 [MEDIUM] Microsoft Update Tuesday: December 2013, some 0-day fixes
## Microsoft Update Tuesday: December 2013, some 0-day fixes
Microsoft’s final update for the year brings us 11 bulletins covering 24 CVE issues.
As is customary, there is the critical IE bulletin, MS13-097 . This time it covers 7 CVE issues. As in other months, this includes a number of use-after-free issues that we’ve come to expect in IE. However this month we also get 2 escalation of privilege vulnerabilities ( CVE-2013-5045 and CVE-2013-5046 ), where an attacker could break out of the low integrity sandbox. This assumes of course that the attacker has first gained remote code execution through another vulnerability and then uses one of these vulnerabilities to execute arbitrary programs.
There is also a critical update for GDI+, MS13-096 . This one fixes the 0-day vulnerability ( C
Talos
Microsoft Update Tuesday: December 2013, some 0-day fixes
blogs_talos·2013-12-10·CVSS 5.5
CVE-2013-5045 [MEDIUM] Microsoft Update Tuesday: December 2013, some 0-day fixes
Microsoft’s final update for the year brings us 11 bulletins covering 24 CVE issues.
As is customary, there is the critical IE bulletin, MS13-097. This time it covers 7 CVE issues. As in other months, this includes a number of use-after-free issues that we’ve come to expect in IE. However this month we also get 2 escalation of privilege vulnerabilities (CVE-2013-5045 and CVE-2013-5046), where an attacker could break out of the low integrity sandbox. This assumes of course that the attacker has first gained remote code execution through another vulnerability and then uses one of these vulnerabilities to execute arbitrary programs.
There is also a critical update for GDI+, MS13-096. This one fixes the 0-day vulnerability (CVE-2013-3906) that is being exploited in the wild. The vulnerabilit
http://www.us-cert.gov/ncas/alerts/TA13-253Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-067https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-105https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19040http://www.us-cert.gov/ncas/alerts/TA13-253Ahttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-067https://docs.microsoft.com/en-us/security-updates/securitybulletins/2013/ms13-105https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A19040
2013-09-11
Published