CVE-2013-0281
- EPSS 0.67%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Pacemaker 1.1.10, when remote Cluster Information Base (CIB) configuration or resource management is enabled, does not limit the duration of connections to the blocking sockets, which allows remote attackers to cause a denial of service (connection b...
CVE-2013-1813
- EPSS 0.09%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
util-linux/mdev.c in BusyBox before 1.21.0 uses 0777 permissions for parent directories when creating nested directories under /dev/, which allows local users to have unknown impact and attack vectors.
CVE-2013-4481
- EPSS 0.03%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Race condition in Luci 0.26.0 creates /var/lib/luci/etc/luci.ini with world-readable permissions before restricting the permissions, which allows local users to read the file and obtain sensitive information such as "authentication secrets."
CVE-2013-4482
- EPSS 0.05%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Untrusted search path vulnerability in python-paste-script (aka paster) in Luci 0.26.0, when started using the initscript, allows local users to gain privileges via a Trojan horse .egg-info file in the (1) current working directory or (2) its parent ...
- EPSS 0.42%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
389 Directory Server 1.2.11.15 (aka Red Hat Directory Server before 8.2.11-14) allows remote authenticated users to cause a denial of service (crash) via multiple @ characters in a GER attribute list in a search request.
- EPSS 1.51%
- Veröffentlicht 02.11.2013 19:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in the reds_handle_ticket function in server/reds.c in SPICE 0.12.0 allows remote attackers to cause a denial of service (crash) via a long password in a SPICE ticket.
- EPSS 0.8%
- Veröffentlicht 24.10.2013 10:53:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device.
CVE-2013-4287
- EPSS 2.02%
- Veröffentlicht 17.10.2013 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Algorithmic complexity vulnerability in Gem::Version::VERSION_PATTERN in lib/rubygems/version.rb in RubyGems before 1.8.23.1, 1.8.24 through 1.8.25, 2.0.x before 2.0.8, and 2.1.x before 2.1.0, as used in Ruby 1.9.0 through 2.0.0p247, allows remote at...
CVE-2013-4397
- EPSS 4.26%
- Veröffentlicht 17.10.2013 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a ...
CVE-2013-4345
- EPSS 0.96%
- Veröffentlicht 10.10.2013 10:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, l...