CVE-2013-4232
- EPSS 1.33%
- Veröffentlicht 10.09.2013 19:55:11
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in the t2p_readwrite_pdf_image function in tools/tiff2pdf.c in libtiff 4.0.3 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted TIFF image.
CVE-2013-4243
- EPSS 18.71%
- Veröffentlicht 10.09.2013 19:55:11
- Zuletzt bearbeitet 29.04.2026 01:13:23
Heap-based buffer overflow in the readgifimage function in the gif2tiff tool in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted height and width values in a GIF ...
CVE-2013-5589
- EPSS 0.42%
- Veröffentlicht 29.08.2013 12:07:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
CVE-2013-2072
- EPSS 0.36%
- Veröffentlicht 28.08.2013 21:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
Buffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with permissions to configure VCPU affinity to cause a denial of service (memory corruption and xend toolstack crash) a...
CVE-2013-2900
- EPSS 0.37%
- Veröffentlicht 21.08.2013 12:17:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
The FilePath::ReferencesParent function in files/file_path.cc in Google Chrome before 29.0.1547.57 on Windows does not properly handle pathname components composed entirely of . (dot) and whitespace characters, which allows remote attackers to conduc...
CVE-2013-2901
- EPSS 1.38%
- Veröffentlicht 21.08.2013 12:17:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
Multiple integer overflows in (1) libGLESv2/renderer/Renderer9.cpp and (2) libGLESv2/renderer/Renderer11.cpp in Almost Native Graphics Layer Engine (ANGLE), as used in Google Chrome before 29.0.1547.57, allow remote attackers to cause a denial of ser...
CVE-2013-2902
- EPSS 0.89%
- Veröffentlicht 21.08.2013 12:17:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in the XSLT ProcessingInstruction implementation in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related t...
CVE-2013-2903
- EPSS 0.89%
- Veröffentlicht 21.08.2013 12:17:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in the HTMLMediaElement::didMoveToNewDocument function in core/html/HTMLMediaElement.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspec...
CVE-2013-2904
- EPSS 1.02%
- Veröffentlicht 21.08.2013 12:17:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in the Document::finishedParsing function in core/dom/Document.cpp in Blink, as used in Google Chrome before 29.0.1547.57, allows remote attackers to cause a denial of service or possibly have unspecified other impact via...
- EPSS 0.14%
- Veröffentlicht 21.08.2013 12:17:56
- Zuletzt bearbeitet 29.04.2026 01:13:23
The SharedMemory::Create function in memory/shared_memory_posix.cc in Google Chrome before 29.0.1547.57 uses weak permissions under /dev/shm/, which allows attackers to obtain sensitive information via direct access to a POSIX shared-memory file.