CVE-2013-4394
- EPSS 0.11%
- Veröffentlicht 28.10.2013 22:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The SetX11Keyboard function in systemd, when PolicyKit Local Authority (PKLA) is used to change the group permissions on the X Keyboard Extension (XKB) layouts description, allows local users in the group to modify the Xorg X11 Server configuration f...
CVE-2013-4365
- EPSS 6.66%
- Veröffentlicht 17.10.2013 23:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.
CVE-2013-4389
- EPSS 1.33%
- Veröffentlicht 17.10.2013 00:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly ...
CVE-2013-2927
- EPSS 2.71%
- Veröffentlicht 16.10.2013 20:55:06
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspeci...
CVE-2013-5807
- EPSS 0.23%
- Veröffentlicht 16.10.2013 17:55:05
- Zuletzt bearbeitet 29.04.2026 01:13:23
Unspecified vulnerability in Oracle MySQL Server 5.5.x through 5.5.32 and 5.6.x through 5.6.12 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Replication.
- EPSS 0.46%
- Veröffentlicht 16.10.2013 15:55:34
- Zuletzt bearbeitet 29.04.2026 01:13:23
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.70 and earlier, 5.5.32 and earlier, and 5.6.12 and earlier allows remote authenticated users to affect availability via unknown vectors related to Optimizer.
CVE-2013-4327
- EPSS 0.03%
- Veröffentlicht 03.10.2013 21:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
systemd does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec proce...
CVE-2013-2919
- EPSS 2.07%
- Veröffentlicht 02.10.2013 10:35:35
- Zuletzt bearbeitet 29.04.2026 01:13:23
Google V8, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVE-2013-4234
- EPSS 3.09%
- Veröffentlicht 16.09.2013 19:14:39
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple heap-based buffer overflows in the (1) abc_MIDI_drum and (2) abc_MIDI_gchord functions in load_abc.cpp in libmodplug 0.8.8.4 and earlier allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute a...
CVE-2013-4233
- EPSS 3.85%
- Veröffentlicht 16.09.2013 19:14:38
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer overflow in the abc_set_parts function in load_abc.cpp in libmodplug 0.8.8.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted P header in an ABC file, which triggers a heap-bas...