- EPSS 1.05%
- Veröffentlicht 09.06.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the dissect_iphc_crtp_fh function in epan/dissectors/packet-ppp.c in the PPP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet.
- EPSS 1.06%
- Veröffentlicht 09.06.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to nbap.cnf and packet-nbap.c.
- EPSS 1.43%
- Veröffentlicht 09.06.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8.8 does not validate return values during checks for data availability, which allows remote attackers to cause a denial of service (application crash) via a crafted packet...
- EPSS 1.26%
- Veröffentlicht 09.06.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The http_payload_subdissector function in epan/dissectors/packet-http.c in the HTTP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 does not properly determine when to use a recursive approach, which allows remote attackers to cause...
- EPSS 1.54%
- Veröffentlicht 09.06.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vwr_read function in wiretap/vwr.c in the Ixia IxVeriWave file parser in Wireshark 1.8.x before 1.8.8 does not validate the relationship between a record length and a trailer length, which allows remote attackers to cause a denial of service (hea...
CVE-2013-2852
- EPSS 0.26%
- Veröffentlicht 07.06.2013 14:03:20
- Zuletzt bearbeitet 11.04.2025 00:51:21
Format string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and including fo...
CVE-2013-2860
- EPSS 0.61%
- Veröffentlicht 05.06.2013 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving access to a database API by a worker process.
CVE-2013-2861
- EPSS 0.61%
- Veröffentlicht 05.06.2013 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.110 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVE-2013-2862
- EPSS 0.62%
- Veröffentlicht 05.06.2013 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Skia, as used in Google Chrome before 27.0.1453.110, does not properly handle GPU acceleration, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
- EPSS 3.18%
- Veröffentlicht 05.06.2013 00:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Google Chrome before 27.0.1453.110 does not properly handle SSL sockets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.