CVE-2013-4342
- EPSS 15.27%
- Veröffentlicht 10.10.2013 00:55:14
- Zuletzt bearbeitet 11.04.2025 00:51:21
xinetd does not enforce the user and group configuration directives for TCPMUX services, which causes these services to be run as root and makes it easier for remote attackers to gain privileges by leveraging another vulnerability in a service.
CVE-2013-4332
- EPSS 1.76%
- Veröffentlicht 09.10.2013 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_mema...
CVE-2013-4288
- EPSS 0.03%
- Veröffentlicht 03.10.2013 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Race condition in PolicyKit (aka polkit) allows local users to bypass intended PolicyKit restrictions and gain privileges by starting a setuid or pkexec process before the authorization check is performed, related to (1) the polkit_unix_process_new A...
CVE-2013-4311
- EPSS 0.02%
- Veröffentlicht 03.10.2013 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
libvirt 1.0.5.x before 1.0.5.6, 0.10.2.x before 0.10.2.8, and 0.9.12.x before 0.9.12.2 allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition in pkcheck via a (1) setuid process or (2)...
CVE-2013-4324
- EPSS 0.07%
- Veröffentlicht 03.10.2013 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race co...
CVE-2013-4326
- EPSS 0.06%
- Veröffentlicht 03.10.2013 21:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process...
CVE-2013-2231
- EPSS 0.05%
- Veröffentlicht 01.10.2013 17:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, a...
- EPSS 3.29%
- Veröffentlicht 30.09.2013 21:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized po...
CVE-2013-2217
- EPSS 0.14%
- Veröffentlicht 23.09.2013 20:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
CVE-2013-1824
- EPSS 2.06%
- Veröffentlicht 16.09.2013 13:02:34
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity...