CVE-2013-5745
- EPSS 18.73%
- Veröffentlicht 01.10.2013 17:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authenticatio...
- EPSS 1.2%
- Veröffentlicht 30.09.2013 22:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecifie...
CVE-2013-4222
- EPSS 0.58%
- Veröffentlicht 30.09.2013 22:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
- EPSS 3.29%
- Veröffentlicht 30.09.2013 21:55:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
The remoteDispatchDomainMemoryStats function in daemon/remote.c in libvirt 0.9.1 through 0.10.1.x, 0.10.2.x before 0.10.2.8, 1.0.x before 1.0.5.6, and 1.1.x before 1.1.2 allows remote authenticated users to cause a denial of service (uninitialized po...
CVE-2013-4314
- EPSS 0.25%
- Veröffentlicht 30.09.2013 21:55:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
The X509Extension in pyOpenSSL before 0.13.1 does not properly handle a '\0' character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a craft...
CVE-2013-4343
- EPSS 0.09%
- Veröffentlicht 25.09.2013 10:31:29
- Zuletzt bearbeitet 29.04.2026 01:13:23
Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and providing an invalid tuntap interface name in a TUNSETIFF ioctl call.
CVE-2013-1060
- EPSS 0.05%
- Veröffentlicht 25.09.2013 10:31:26
- Zuletzt bearbeitet 29.04.2026 01:13:23
A certain Ubuntu build procedure for perf, as distributed in the Linux kernel packages in Ubuntu 10.04 LTS, 12.04 LTS, 12.10, 13.04, and 13.10, sets the HOME environment variable to the ~buildd directory and consequently reads the system configuratio...
CVE-2013-4202
- EPSS 0.84%
- Veröffentlicht 16.09.2013 19:14:38
- Zuletzt bearbeitet 29.04.2026 01:13:23
The (1) backup (api/contrib/backups.py) and (2) volume transfer (contrib/volume_transfer.py) APIs in OpenStack Cinder Grizzly 2013.1.3 and earlier allows remote attackers to cause a denial of service (resource consumption and crash) via an XML Entity...
- EPSS 1.1%
- Veröffentlicht 20.08.2013 22:55:04
- Zuletzt bearbeitet 29.04.2026 01:13:23
The (1) red_channel_pipes_add_type and (2) red_channel_pipes_add_empty_msg functions in server/red_channel.c in SPICE before 0.12.4 do not properly perform ring loops, which might allow remote attackers to cause a denial of service (reachable asserti...
CVE-2013-4242
- EPSS 0.09%
- Veröffentlicht 19.08.2013 23:55:09
- Zuletzt bearbeitet 29.04.2026 01:13:23
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.