CVE-2013-4345
- EPSS 0.96%
- Published 10.10.2013 10:55:06
- Last modified 11.04.2025 00:51:21
Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, l...
CVE-2013-2207
- EPSS 0.07%
- Published 09.10.2013 22:55:02
- Last modified 11.04.2025 00:51:21
pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file sys...
- EPSS 1.2%
- Published 30.09.2013 22:55:04
- Last modified 11.04.2025 00:51:21
Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecifie...
CVE-2013-4222
- EPSS 0.58%
- Published 30.09.2013 22:55:04
- Last modified 11.04.2025 00:51:21
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
CVE-2013-1888
- EPSS 0.04%
- Published 17.08.2013 06:54:57
- Last modified 11.04.2025 00:51:21
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
- EPSS 86.81%
- Published 06.08.2013 02:56:00
- Last modified 11.04.2025 00:51:21
Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) via a malformed packet.
CVE-2013-4854
- EPSS 65.17%
- Published 29.07.2013 13:59:37
- Last modified 11.04.2025 00:51:21
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertio...
CVE-2013-2028
- EPSS 92.54%
- Published 20.07.2013 03:37:20
- Last modified 11.04.2025 00:51:21
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which t...
CVE-2013-0237
- EPSS 0.43%
- Published 08.07.2013 20:55:00
- Last modified 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
CVE-2013-2064
- EPSS 0.94%
- Published 15.06.2013 19:55:01
- Last modified 11.04.2025 00:51:21
Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.