CVE-2012-0425
- EPSS 1.11%
- Veröffentlicht 02.12.2013 04:36:26
- Zuletzt bearbeitet 29.04.2026 01:13:23
LanItems.ycp in save_y2logs in yast2-network before 2.24.4 in SUSE YaST writes cleartext Wi-Fi credentials to the y2log log file, which allows context-dependent attackers to obtain sensitive information by reading the (1) WIRELESS_WPA_PASSWORD or (2)...
CVE-2012-0427
- EPSS 0.49%
- Veröffentlicht 02.12.2013 04:36:26
- Zuletzt bearbeitet 29.04.2026 01:13:23
yast2-add-on-creator in SUSE inst-source-utils 2008.11.26 before 2008.11.26-0.9.1 and 2012.9.13 before 2012.9.13-0.8.1 allows local users to gain privileges via a crafted (1) file name or (2) directory name.
- EPSS 4.58%
- Veröffentlicht 28.11.2013 04:37:39
- Zuletzt bearbeitet 29.04.2026 01:13:23
The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted inte...
CVE-2013-4509
- EPSS 0.34%
- Veröffentlicht 23.11.2013 19:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user ...
CVE-2013-0221
- EPSS 7.24%
- Veröffentlicht 23.11.2013 18:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the sort command, when using the (1) -d or (2) -M switch, which triggers a stack-based...
CVE-2013-0222
- EPSS 0.38%
- Veröffentlicht 23.11.2013 18:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the uniq command, which triggers a stack-based buffer overflow in the alloca function.
CVE-2013-0223
- EPSS 0.51%
- Veröffentlicht 23.11.2013 18:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The SUSE coreutils-i18n.patch for GNU coreutils allows context-dependent attackers to cause a denial of service (segmentation fault and crash) via a long string to the join command, when using the -i switch, which triggers a stack-based buffer overfl...
CVE-2013-4547
- EPSS 67.72%
- Veröffentlicht 23.11.2013 18:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
CVE-2013-6858
- EPSS 1.73%
- Veröffentlicht 23.11.2013 17:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
CVE-2013-6375
- EPSS 1.39%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified ...