- EPSS 4%
- Veröffentlicht 16.05.2013 11:45:31
- Zuletzt bearbeitet 11.04.2025 00:51:21
Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows and Mac OS X, before 10.3.183.86 and 11.x before 11.2.202.285 on Linux, before 11.1.111.54 on Android 2.x and 3.x, and before 11.1.115.58 on Android 4.x; Adobe AIR before 3...
CVE-2013-1675
- EPSS 2.57%
- Veröffentlicht 16.05.2013 11:45:30
- Zuletzt bearbeitet 11.04.2025 00:51:21
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale funct...
CVE-2013-1845
- EPSS 1.84%
- Veröffentlicht 02.05.2013 14:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting or (2) deleting a large number of properties for a...
- EPSS 1.92%
- Veröffentlicht 02.05.2013 14:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) via a LOCK on an activity URL.
CVE-2013-1926
- EPSS 0.7%
- Veröffentlicht 29.04.2013 22:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets vi...
CVE-2013-1927
- EPSS 2.19%
- Veröffentlicht 29.04.2013 22:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."
CVE-2013-0233
- EPSS 68.82%
- Veröffentlicht 25.04.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Devise gem 2.2.x before 2.2.3, 2.1.x before 2.1.3, 2.0.x before 2.0.5, and 1.5.x before 1.5.4 for Ruby, when using certain databases, does not properly perform type conversion when performing database queries, which might allow remote attackers to ca...
CVE-2013-0338
- EPSS 0.25%
- Veröffentlicht 25.04.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entit...
CVE-2013-1915
- EPSS 4.85%
- Veröffentlicht 25.04.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference...
- EPSS 2.64%
- Veröffentlicht 19.04.2013 11:44:26
- Zuletzt bearbeitet 11.04.2025 00:51:21
The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of s...