CVE-2013-1675
- EPSS 4.74%
- Veröffentlicht 16.05.2013 11:45:30
- Zuletzt bearbeitet 22.10.2025 01:15:48
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale funct...
- EPSS 7.63%
- Veröffentlicht 13.05.2013 23:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer underflow in the cli_scanpe function in pe.c in ClamAV before 0.97.8 allows remote attackers to cause a denial of service (crash) via a skewed offset larger than the size of the PE section in a UPX packed executable, which triggers an out-of-...
CVE-2013-2021
- EPSS 14.52%
- Veröffentlicht 13.05.2013 23:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
pdf.c in ClamAV 0.97.1 through 0.97.7 allows remote attackers to cause a denial of service (out-of-bounds-read) via a crafted length value in an encrypted PDF file.
CVE-2013-1940
- EPSS 0.11%
- Veröffentlicht 13.05.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain sensitive information, as demonstrated by reading pas...
- EPSS 0.25%
- Veröffentlicht 02.05.2013 14:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history in...
- EPSS 0.36%
- Veröffentlicht 02.05.2013 14:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors ...
CVE-2013-1926
- EPSS 0.88%
- Veröffentlicht 29.04.2013 22:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets vi...
CVE-2013-1927
- EPSS 2.23%
- Veröffentlicht 29.04.2013 22:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."
- EPSS 2.48%
- Veröffentlicht 29.04.2013 22:55:08
- Zuletzt bearbeitet 11.04.2025 00:51:21
The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.
CVE-2013-0338
- EPSS 0.3%
- Veröffentlicht 25.04.2013 23:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entit...