CVE-2013-1776
- EPSS 0.05%
- Published 08.04.2013 17:55:01
- Last modified 11.04.2025 00:51:21
sudo 1.3.5 through 1.7.10 and 1.8.0 through 1.8.5, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via ...
CVE-2013-2776
- EPSS 0.08%
- Published 08.04.2013 17:55:01
- Last modified 11.04.2025 00:51:21
sudo 1.3.5 through 1.7.10p5 and 1.8.0 through 1.8.6p6, when running on systems without /proc or the sysctl function with the tty_tickets option enabled, does not properly validate the controlling terminal device, which allows local users with sudo pe...
CVE-2013-2777
- EPSS 0.05%
- Published 08.04.2013 17:55:01
- Last modified 11.04.2025 00:51:21
sudo before 1.7.10p5 and 1.8.x before 1.8.6p6, when the tty_tickets option is enabled, does not properly validate the controlling terminal device, which allows local users with sudo permissions to hijack the authorization of another terminal via vect...
CVE-2013-0971
- EPSS 1.47%
- Published 15.03.2013 20:55:11
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in PDFKit in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted ink annotations in a PDF document.
CVE-2013-0973
- EPSS 0.35%
- Published 15.03.2013 20:55:11
- Last modified 11.04.2025 00:51:21
Software Update in Apple Mac OS X through 10.7.5 does not prevent plugin loading within the marketing-text WebView, which allows man-in-the-middle attackers to execute plugin code by modifying the client-server data stream.
CVE-2013-0976
- EPSS 1.26%
- Published 15.03.2013 20:55:11
- Last modified 11.04.2025 00:51:21
IOAcceleratorFamily in Apple Mac OS X before 10.8.3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted graphics image.
CVE-2013-0966
- EPSS 0.24%
- Published 15.03.2013 20:55:10
- Last modified 11.04.2025 00:51:21
The Apple mod_hfs_apple module for the Apache HTTP Server in Apple Mac OS X before 10.8.3 does not properly handle ignorable Unicode characters, which allows remote attackers to bypass intended directory authentication requirements via a crafted path...
CVE-2013-0967
- EPSS 0.33%
- Published 15.03.2013 20:55:10
- Last modified 11.04.2025 00:51:21
CoreTypes in Apple Mac OS X before 10.8.3 includes JNLP files in the list of safe file types, which allows remote attackers to bypass a Java plug-in disabled setting, and trigger the launch of Java Web Start applications, via a crafted web site.
CVE-2013-0969
- EPSS 0.06%
- Published 15.03.2013 20:55:10
- Last modified 11.04.2025 00:51:21
Login Window in Apple Mac OS X before 10.8.3 does not prevent application launching with the VoiceOver feature, which allows physically proximate attackers to bypass authentication and make arbitrary System Preferences changes via unspecified use of ...
CVE-2013-0970
- EPSS 0.4%
- Published 15.03.2013 20:55:10
- Last modified 11.04.2025 00:51:21
Messages in Apple Mac OS X before 10.8.3 allows remote attackers to bypass the FaceTime call-confirmation prompt via a crafted FaceTime: URL.