- EPSS 0.46%
- Veröffentlicht 20.03.2013 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Puppet 2.7.x before 2.7.21 and 3.1.x before 3.1.1, and Puppet Enterprise 2.7.x before 2.7.2, does not properly negotiate the SSL protocol between client and master, which allows remote attackers to conduct SSLv2 downgrade attacks against SSLv3 sessio...
- EPSS 0.38%
- Veröffentlicht 20.03.2013 16:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The default configuration for puppet masters 0.25.0 and later in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, allows remote authenticated nodes to submit reports for oth...
CVE-2013-2566
- EPSS 90.32%
- Veröffentlicht 15.03.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The RC4 algorithm, as used in the TLS protocol and SSL protocol, has many single-byte biases, which makes it easier for remote attackers to conduct plaintext-recovery attacks via statistical analysis of ciphertext in a large number of sessions that u...
CVE-2013-0249
- EPSS 44.2%
- Veröffentlicht 08.03.2013 22:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7.26.0 through 7.28.1, when negotiating SASL DIGEST-MD5 authentication, allows remote attackers to cause a denial of service (crash...
CVE-2013-0256
- EPSS 3.58%
- Veröffentlicht 01.03.2013 05:40:17
- Zuletzt bearbeitet 11.04.2025 00:51:21
darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.
- EPSS 1.2%
- Veröffentlicht 24.02.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
store/swift.py in OpenStack Glance Essex (2012.1), Folsom (2012.2) before 2012.2.3, and Grizzly, when in Swift single tenant mode, logs the Swift endpoint's user name and password in cleartext when the endpoint is misconfigured or unusable, allows re...
- EPSS 2.96%
- Veröffentlicht 24.02.2013 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
OpenStack Keystone Essex 2012.1.3 and earlier, Folsom 2012.2.3 and earlier, and Grizzly grizzly-2 and earlier allows remote attackers to cause a denial of service (disk consumption) via many invalid token requests that trigger excessive generation of...
CVE-2012-5624
- EPSS 1.87%
- Veröffentlicht 24.02.2013 19:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The XMLHttpRequest object in Qt before 4.8.4 enables http redirection to the file scheme, which allows man-in-the-middle attackers to force the read of arbitrary local files and possibly obtain sensitive information via a file: URL to a QML applicati...
CVE-2012-6093
- EPSS 2.28%
- Veröffentlicht 24.02.2013 19:55:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
The QSslSocket::sslErrors function in Qt before 4.6.5, 4.7.x before 4.7.6, 4.8.x before 4.8.5, when using certain versions of openSSL, uses an "incompatible structure layout" that can read memory from the wrong location, which causes Qt to report an ...
CVE-2013-0894
- EPSS 0.47%
- Veröffentlicht 23.02.2013 21:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Buffer overflow in the vorbis_parse_setup_hdr_floors function in the Vorbis decoder in vorbisdec.c in libavcodec in FFmpeg through 1.1.3, as used in Google Chrome before 25.0.1364.97 on Windows and Linux and before 25.0.1364.99 on Mac OS X and other ...