- EPSS 2.48%
- Veröffentlicht 29.04.2013 22:55:08
- Zuletzt bearbeitet 29.04.2026 01:13:23
The tailMatch function in cookie.c in cURL and libcurl before 7.30.0 does not properly match the path domain when sending cookies, which allows remote attackers to steal cookies via a matching suffix in the domain of a URL.
CVE-2013-0338
- EPSS 0.67%
- Veröffentlicht 25.04.2013 23:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
libxml2 2.9.0 and earlier allows context-dependent attackers to cause a denial of service (CPU and memory consumption) via an XML file containing an entity declaration with long replacement text and many references to this entity, aka "internal entit...
CVE-2013-2423
- EPSS 93.4%
- Veröffentlicht 17.04.2013 18:55:07
- Zuletzt bearbeitet 22.04.2026 13:06:26
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows remote attackers to affect integrity via unknown vectors related to HotSpot. NOTE: the previous information is...
CVE-2013-1899
- EPSS 81.12%
- Veröffentlicht 04.04.2013 17:55:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
Argument injection vulnerability in PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, and 9.0.x before 9.0.13 allows remote attackers to cause a denial of service (file corruption), and allows remote authenticated users to modify configuration setti...
CVE-2013-1900
- EPSS 0.57%
- Veröffentlicht 04.04.2013 17:55:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
PostgreSQL 9.2.x before 9.2.4, 9.1.x before 9.1.9, 9.0.x before 9.0.13, and 8.4.x before 8.4.17, when using OpenSSL, generates insufficiently random numbers, which might allow remote authenticated users to have an unspecified impact via vectors relat...
- EPSS 0.22%
- Veröffentlicht 04.04.2013 17:55:00
- Zuletzt bearbeitet 29.04.2026 01:13:23
PostgreSQL 9.2.x before 9.2.4 and 9.1.x before 9.1.9 does not properly check REPLICATION privileges, which allows remote authenticated users to bypass intended backup restrictions by calling the (1) pg_start_backup or (2) pg_stop_backup functions.
- EPSS 2.68%
- Veröffentlicht 03.04.2013 11:56:21
- Zuletzt bearbeitet 29.04.2026 01:13:23
The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other pr...
CVE-2013-0800
- EPSS 2.8%
- Veröffentlicht 03.04.2013 11:56:21
- Zuletzt bearbeitet 29.04.2026 01:13:23
Integer signedness error in the pixman_fill_sse2 function in pixman-sse2.c in Pixman, as distributed with Cairo and used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, Se...
CVE-2012-6129
- EPSS 2.68%
- Veröffentlicht 03.04.2013 00:55:01
- Zuletzt bearbeitet 29.04.2026 01:13:23
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol ...
CVE-2013-1799
- EPSS 0.56%
- Veröffentlicht 02.04.2013 03:23:26
- Zuletzt bearbeitet 29.04.2026 01:13:23
Gnome Online Accounts (GOA) 3.6.x before 3.6.3 and 3.7.x before 3.7.91, does not properly validate SSL certificates when creating accounts for providers who use the libsoup library, which allows man-in-the-middle attackers to obtain sensitive informa...