CVE-2013-4508
- EPSS 2.91%
- Veröffentlicht 08.11.2013 04:47:22
- Zuletzt bearbeitet 11.04.2025 00:51:21
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
CVE-2013-4135
- EPSS 0.28%
- Veröffentlicht 05.11.2013 21:55:12
- Zuletzt bearbeitet 11.04.2025 00:51:21
The vos command in OpenAFS 1.6.x before 1.6.5, when using the -encrypt option, only enables integrity protection and sends data in cleartext, which allows remote attackers to obtain sensitive information by sniffing the network.
CVE-2013-4134
- EPSS 0.15%
- Veröffentlicht 05.11.2013 21:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenAFS before 1.4.15, 1.6.x before 1.6.5, and 1.7.x before 1.7.26 uses weak encryption (DES) for Kerberos keys, which makes it easier for remote attackers to obtain the service key.
CVE-2013-4494
- EPSS 0.31%
- Veröffentlicht 02.11.2013 18:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Xen before 4.1.x, 4.2.x, and 4.3.x does not take the page_alloc_lock and grant_table.lock in the same order, which allows local guest administrators with access to multiple vcpus to cause a denial of service (host deadlock) via unspecified vectors.
CVE-2013-4391
- EPSS 3.7%
- Veröffentlicht 28.10.2013 22:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the valid_user_field function in journal/journald-native.c in systemd allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large journal data field, which triggers a heap-based buf...
CVE-2013-4394
- EPSS 0.11%
- Veröffentlicht 28.10.2013 22:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration f...
CVE-2013-4365
- EPSS 6.66%
- Veröffentlicht 17.10.2013 23:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.
CVE-2013-4389
- EPSS 1.33%
- Veröffentlicht 17.10.2013 00:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly ...
CVE-2013-2927
- EPSS 2.71%
- Veröffentlicht 16.10.2013 20:55:06
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspeci...
CVE-2013-5807
- EPSS 0.23%
- Veröffentlicht 16.10.2013 17:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication.