CVE-2013-1872
- EPSS 1.13%
- Veröffentlicht 19.08.2013 23:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Intel drivers in Mesa 8.0.x and 9.0.x allow context-dependent attackers to cause a denial of service (reachable assertion and crash) and possibly execute arbitrary code via vectors involving 3d graphics that trigger an out-of-bounds array access,...
CVE-2013-2145
- EPSS 0.2%
- Veröffentlicht 19.08.2013 23:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The cpansign verify functionality in the Module::Signature module before 0.72 for Perl allows attackers to bypass the signature check and execute arbitrary code via a SIGNATURE file with a "special unknown cipher" that references an untrusted module ...
CVE-2013-4238
- EPSS 4.03%
- Veröffentlicht 18.08.2013 02:52:22
- Zuletzt bearbeitet 11.04.2025 00:51:21
The ssl.match_hostname function in the SSL module in Python 2.6 through 3.4 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof ar...
CVE-2013-2132
- EPSS 2.23%
- Veröffentlicht 15.08.2013 17:55:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef....
CVE-2013-2126
- EPSS 3.23%
- Veröffentlicht 14.08.2013 15:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple double free vulnerabilities in the LibRaw::unpack function in libraw_cxx.cpp in LibRaw before 0.15.2 allow context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed full-...
CVE-2013-4115
- EPSS 75.06%
- Veröffentlicht 09.08.2013 22:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to cause a denial of service (memory corruption and server termination) via a long name in a DNS lookup request.
- EPSS 86.81%
- Veröffentlicht 06.08.2013 02:56:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
CVE-2013-2174
- EPSS 9.13%
- Veröffentlicht 31.07.2013 13:20:25
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the curl_easy_unescape function in lib/escape.c in cURL and libcurl 7.7 through 7.30.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted string endi...
CVE-2013-1968
- EPSS 0.64%
- Veröffentlicht 31.07.2013 13:20:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote authenticated users to cause a denial of service (FSFS repository corruption) via a newline character in a file name.
CVE-2013-2088
- EPSS 6.49%
- Veröffentlicht 31.07.2013 13:20:24
- Zuletzt bearbeitet 11.04.2025 00:51:21
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.