CVE-2011-3593
- EPSS 0.32%
- Published 08.06.2013 13:05:55
- Last modified 11.04.2025 00:51:21
A certain Red Hat patch to the vlan_hwaccel_do_receive function in net/8021q/vlan_core.c in the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows remote attackers to cause a denial of service (system crash) via priority-tagged VLAN fram...
CVE-2012-6137
- EPSS 0.19%
- Published 21.05.2013 18:55:01
- Last modified 11.04.2025 00:51:21
rhn-migrate-classic-to-rhsm tool in Red Hat subscription-manager does not verify the Red Hat Network Classic server's X.509 certificate when migrating to a Certificate-based Red Hat Network, which allows remote man-in-the-middle attackers to obtain s...
CVE-2013-2015
- EPSS 0.09%
- Published 29.04.2013 14:55:04
- Last modified 11.04.2025 00:51:21
The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a cr...
CVE-2013-3301
- EPSS 0.34%
- Published 29.04.2013 14:55:04
- Last modified 11.04.2025 00:51:21
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write acce...
CVE-2013-1928
- EPSS 0.06%
- Published 29.04.2013 14:55:03
- Last modified 11.04.2025 00:51:21
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted...
CVE-2012-4546
- EPSS 0.72%
- Published 03.04.2013 00:55:01
- Last modified 11.04.2025 00:51:21
The default configuration for IPA servers in Red Hat Enterprise Linux 6, when revoking a certificate from an Identity Management replica, does not properly update another Identity Management replica, which causes inconsistent Certificate Revocation L...
- EPSS 39.41%
- Published 28.03.2013 23:55:01
- Last modified 11.04.2025 00:51:21
MariaDB 5.5.x before 5.5.30, 5.3.x before 5.3.13, 5.2.x before 5.2.15, and 5.1.x before 5.1.68, and Oracle MySQL 5.1.69 and earlier, 5.5.31 and earlier, and 5.6.11 and earlier allows remote attackers to cause a denial of service (crash) via a crafted...
- EPSS 1.8%
- Published 19.03.2013 22:55:01
- Last modified 11.04.2025 00:51:21
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input ...
CVE-2013-1855
- EPSS 0.54%
- Published 19.03.2013 22:55:01
- Last modified 11.04.2025 00:51:21
The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) character...
CVE-2013-1857
- EPSS 0.63%
- Published 19.03.2013 22:55:01
- Last modified 11.04.2025 00:51:21
The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characte...