CVE-2013-4326
- EPSS 0.06%
- Published 03.10.2013 21:55:04
- Last modified 11.04.2025 00:51:21
RealtimeKit (aka rtkit) 0.5 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process...
CVE-2013-2231
- EPSS 0.05%
- Published 01.10.2013 17:55:03
- Last modified 11.04.2025 00:51:21
Unquoted Windows search path vulnerability in the QEMU Guest Agent service for Red Hat Enterprise Linux Desktop 6, HPC Node 6, Server 6, Workstation 6, Desktop Supplementary 6, Server Supplementary 6, Supplementary AUS 6.4, Supplementary EUS 6.4.z, a...
- EPSS 3.29%
- Published 30.09.2013 21:55:09
- Last modified 11.04.2025 00:51:21
The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized po...
CVE-2013-2217
- EPSS 0.11%
- Published 23.09.2013 20:55:07
- Last modified 11.04.2025 00:51:21
cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.
CVE-2013-1824
- EPSS 1.67%
- Published 16.09.2013 13:02:34
- Last modified 11.04.2025 00:51:21
The SOAP parser in PHP before 5.3.22 and 5.4.x before 5.4.12 allows remote attackers to read arbitrary files via a SOAP WSDL file containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity...
CVE-2013-1872
- EPSS 1.13%
- Published 19.08.2013 23:55:08
- Last modified 11.04.2025 00:51:21
The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access,...
CVE-2013-4248
- EPSS 9.89%
- Published 18.08.2013 02:52:23
- Last modified 11.04.2025 00:51:21
The openssl_x509_parse function in openssl.c in the OpenSSL module in PHP before 5.4.18 and 5.5.x before 5.5.2 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-...
- EPSS 86.81%
- Published 06.08.2013 02:56:00
- Last modified 11.04.2025 00:51:21
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
CVE-2013-2174
- EPSS 9.13%
- Published 31.07.2013 13:20:25
- Last modified 11.04.2025 00:51:21
Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string endi...
CVE-2013-4854
- EPSS 65.17%
- Published 29.07.2013 13:59:37
- Last modified 11.04.2025 00:51:21
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertio...