- EPSS 3.44%
- Veröffentlicht 19.03.2013 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input ...
CVE-2013-1855
- EPSS 2.64%
- Veröffentlicht 19.03.2013 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) character...
CVE-2013-1857
- EPSS 1.87%
- Veröffentlicht 19.03.2013 22:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characte...
CVE-2012-6537
- EPSS 0.38%
- Veröffentlicht 15.03.2013 20:55:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.
CVE-2012-6538
- EPSS 0.35%
- Veröffentlicht 15.03.2013 20:55:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive information from kernel heap memory by leveraging the CAP_NE...
CVE-2012-6542
- EPSS 0.35%
- Veröffentlicht 15.03.2013 20:55:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that le...
CVE-2012-6544
- EPSS 0.37%
- Veröffentlicht 15.03.2013 20:55:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that targets the (1) L2CAP or (2)...
CVE-2012-6545
- EPSS 0.37%
- Veröffentlicht 15.03.2013 20:55:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.
CVE-2012-6546
- EPSS 0.4%
- Veröffentlicht 15.03.2013 20:55:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
CVE-2012-6548
- EPSS 0.43%
- Veröffentlicht 15.03.2013 20:55:07
- Zuletzt bearbeitet 29.04.2026 01:13:23
The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap memory via a crafted application.