- EPSS 2.75%
- Veröffentlicht 11.12.2013 15:55:07
- Zuletzt bearbeitet 25.11.2025 17:50:16
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and app...
- EPSS 0.88%
- Veröffentlicht 11.12.2013 15:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via u...
CVE-2013-6410
- EPSS 0.32%
- Veröffentlicht 07.12.2013 20:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
nbd-server in Network Block Device (nbd) before 3.5 does not properly check IP addresses, which might allow remote attackers to bypass intended access restrictions via an IP address that has a partial match in the authfile configuration file.
CVE-2012-6150
- EPSS 0.14%
- Veröffentlicht 03.12.2013 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended a...
- EPSS 17.3%
- Veröffentlicht 28.11.2013 04:37:39
- Zuletzt bearbeitet 11.04.2025 00:51:21
The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted inte...
CVE-2013-1058
- EPSS 0.67%
- Veröffentlicht 23.11.2013 18:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
CVE-2013-4459
- EPSS 0.06%
- Veröffentlicht 23.11.2013 18:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
LightDM 1.7.5 through 1.8.3 and 1.9.x before 1.9.2 does not apply the AppArmor profile to the Guest account, which allows local users to bypass intended restrictions by leveraging the Guest account.
CVE-2013-6858
- EPSS 0.76%
- Veröffentlicht 23.11.2013 17:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
- EPSS 1.19%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
ctcphandler.cpp in Quassel before 0.6.3 and 0.7.x before 0.7.1 allows remote attackers to cause a denial of service (unresponsive IRC) via multiple Client-To-Client Protocol (CTCP) requests in a PRIVMSG message.
CVE-2013-4473
- EPSS 2.27%
- Veröffentlicht 23.11.2013 11:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in the extractPages function in utils/pdfseparate.cc in poppler before 0.24.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a source filename.