Mission and Overview
NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA).
Resource Status
NVD contains:
CVE Vulnerabilities
56440
Checklists
221
US-CERT Alerts
246
US-CERT Vuln Notes
2721
OVAL Queries
8140
CPE Names
73311

Last updated: Fri May 24 13:39:44 EDT 2013

CVE Publication rate: 12.47

Email List

NVD provides four mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists

Workload Index

Vulnerability Workload Index: 6.49

About Us
NVD is a product of the NIST Computer Security Division and is sponsored by the Department of Homeland Security's National Cyber Security Division. It supports the U.S. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. It is the U.S. government content repository for the Security Content Automation Protocol (SCAP).
CVE-2013-1022

Summary: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted mvhd atoms in a movie file.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-1021

Summary: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted JPEG data in a movie file.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-1020

Summary: Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JPEG data in a movie file.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-1019

Summary: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with Sorenson encoding.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-1018

Summary: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.264 encoding.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-1017

Summary: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted dref atoms in a movie file.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-1016

Summary: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file with H.263 encoding.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-1015

Summary: Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted TeXML file.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-0989

Summary: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted MP3 file.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-0988

Summary: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted FPX file.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-0987

Summary: Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted QTIF file.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2013-0986

Summary: Buffer overflow in Apple QuickTime before 7.7.4 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted enof atoms in a movie file.

Published: 05/24/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2012-4697

Summary: TURCK BL20 Programmable Gateway and BL67 Programmable Gateway have hardcoded accounts, which allows remote attackers to obtain administrative access via an FTP session.

Published: 05/23/2013
CVSS Severity: 10.0 (HIGH)
CVE-2011-4520

Summary: Heap-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.

Published: 05/23/2013
CVSS Severity: 4.3 (MEDIUM)
CVE-2011-4519

Summary: Stack-based buffer overflow in an ActiveX component in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to cause a denial of service via a crafted web page.

Published: 05/23/2013
CVSS Severity: 5.0 (MEDIUM)
CVE-2011-4518

Summary: Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.

Published: 05/23/2013
CVSS Severity: 5.0 (MEDIUM)
CVE-2012-6563

Summary: engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.

Published: 05/23/2013
CVSS Severity: 4.3 (MEDIUM)
CVE-2012-6562

Summary: engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbitrary accounts.

Published: 05/23/2013
CVSS Severity: 6.8 (MEDIUM)
CVE-2012-6561

Summary: Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the view parameter to index.php. NOTE: some of these details are obtained from third party information.

Published: 05/23/2013
CVSS Severity: 4.3 (MEDIUM)
CVE-2012-6560

Summary: SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands via the status parameter.

Published: 05/23/2013
CVSS Severity: 7.5 (HIGH)