CVE-2013-4000
published 2013-12-14CVE-2013-4000: Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of…
PriorityP425medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
0.57%
43.3th percentile
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | cognos_command_center | <= 10.1 | — |
| ibm | cognos_command_center | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_cisco6.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6hg5-jqvr-2wj8: Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10
ghsa_unreviewed·2022-05-17
CVE-2013-4000 [MEDIUM] CWE-352 GHSA-6hg5-jqvr-2wj8: Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10
Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.
Kernel
pipe: limit the per-user amount of pages allocated in pipes
kernel_security·2016-01-18·CVSS 6.2
CVE-2013-4312 [MEDIUM] pipe: limit the per-user amount of pages allocated in pipes
pipe: limit the per-user amount of pages allocated in pipes
On no-so-small systems, it is possible for a single process to cause an
OOM condition by filling large pipes with data that are never read. A
typical process filling 4000 pipes with 1 MB of data will use 4 GB of
memory. On small systems it may be tricky to set the pipe max size to
prevent this from happening.
This patch makes it possible to enforce a per-user soft limit above
which new pipes will be limited to a single page, effectively limiting
them to 4 kB each, as well as a hard limit above which no new pipes may
be created for this user. This has the effect of protecting the system
against memory abuse without hurting other users, and still allowing
pipes to work correctly though with less data at once.
The limit are contro
Cisco
Cisco Nexus 4000 Series Switches IPv6 Denial of Service Vulnerability
vendor_cisco·2013-11-13·CVSS 6.1
CVE-2013-6683 [MEDIUM] CWE-399 Cisco Nexus 4000 Series Switches IPv6 Denial of Service Vulnerability
Cisco Nexus 4000 Series Switches IPv6 Denial of Service Vulnerability
A vulnerability in the IP version 6 (IPv6) packet handling routine of Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to cause a device to stop responding to neighbor solicitation (NS) requests, causing a limited denial of service (DoS) condition.
The vulnerability is due to improper processing of adjacencies in the IPv6 neighbor table. An attacker could exploit this vulnerability by sending a sequence of malformed IPv6 packets to an affected device. An exploit could allow the attacker to cause a device to stop responding to NS requests, causing a limited DoS condition.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, an a
Cisco
Cisco Video Surveillance 4000 Series IP Camera Default Credential Vulnerability
vendor_cisco·2013-10-15·CVSS 6.4
CVE-2013-5535 [MEDIUM] CWE-255 Cisco Video Surveillance 4000 Series IP Camera Default Credential Vulnerability
Cisco Video Surveillance 4000 Series IP Camera Default Credential Vulnerability
A vulnerability in the analytics page of the Cisco Video Surveillance 4000 Series IP Camera could allow an unauthenticated, remote attacker to gain access to the analytics pages of a Cisco Video Surveillance 4000 Series IP Camera.
The vulnerability is due to an undocumented user account with a hard-coded password. An attacker could exploit this vulnerability by accessing the analytics pages of the Cisco Video Surveillance 4000 Series IP Camera using the hard-coded credentials. An exploit could allow the attacker to view the analytics page, which contains a view of the video feed.
Cisco has confirmed the vulnerability in a security notice and released software updates.
To exploit this vulnerability, it is l
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-12-14
Published