- EPSS 0.54%
- Veröffentlicht 09.10.2013 14:54:26
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cumin, as used in Red Hat Enterprise MRG 2.4, allows remote attackers to cause a denial of service (CPU and memory consumption) via a crafted Ajax update request.
- EPSS 52.33%
- Veröffentlicht 01.10.2013 20:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
MongoDB before 2.0.9 and 2.2.x before 2.2.4 does not properly validate requests to the nativeHelper function in SpiderMonkey, which allows remote authenticated users to cause a denial of service (invalid memory access and server crash) or execute arb...
CVE-2013-1909
- EPSS 0.59%
- Veröffentlicht 23.08.2013 16:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL serve...
CVE-2013-2164
- EPSS 0.07%
- Veröffentlicht 04.07.2013 21:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive.
CVE-2013-3301
- EPSS 0.34%
- Veröffentlicht 29.04.2013 14:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write acce...
CVE-2013-2015
- EPSS 0.09%
- Veröffentlicht 29.04.2013 14:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a cr...
CVE-2013-2548
- EPSS 0.05%
- Veröffentlicht 15.03.2013 20:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value during a copy operation, which allows local users to obtain sensitive infor...
CVE-2013-2547
- EPSS 0.07%
- Veröffentlicht 15.03.2013 20:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which allows local users to obtain sensitive information fr...
CVE-2013-2546
- EPSS 0.05%
- Veröffentlicht 15.03.2013 20:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive information from kernel stack memory by leveraging the CAP_NE...
CVE-2012-4462
- EPSS 0.69%
- Veröffentlicht 14.03.2013 03:10:23
- Zuletzt bearbeitet 11.04.2025 00:51:21
aviary/jobcontrol.py in Condor, as used in Red Hat Enterprise MRG 2.3, when removing a job, allows remote attackers to cause a denial of service (condor_schedd restart) via square brackets in the cproc option.