- EPSS 1.51%
- Published 02.11.2013 19:55:04
- Last modified 11.04.2025 00:51:21
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
- EPSS 0.8%
- Published 24.10.2013 10:53:09
- Last modified 11.04.2025 00:51:21
Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device.
CVE-2013-4287
- EPSS 2.02%
- Published 17.10.2013 23:55:04
- Last modified 11.04.2025 00:51:21
Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote at...
CVE-2013-4397
- EPSS 4.26%
- Published 17.10.2013 23:55:04
- Last modified 11.04.2025 00:51:21
Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a ...
CVE-2013-4345
- EPSS 0.96%
- Published 10.10.2013 10:55:06
- Last modified 11.04.2025 00:51:21
Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, l...
CVE-2013-4342
- EPSS 15.27%
- Published 10.10.2013 00:55:14
- Last modified 11.04.2025 00:51:21
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.
CVE-2013-4332
- EPSS 1.94%
- Published 09.10.2013 22:55:02
- Last modified 11.04.2025 00:51:21
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_mema...
CVE-2013-4288
- EPSS 0.03%
- Published 03.10.2013 21:55:04
- Last modified 11.04.2025 00:51:21
Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new A...
CVE-2013-4311
- EPSS 0.02%
- Published 03.10.2013 21:55:04
- Last modified 11.04.2025 00:51:21
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2)...
CVE-2013-4324
- EPSS 0.07%
- Published 03.10.2013 21:55:04
- Last modified 11.04.2025 00:51:21
spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race co...