- EPSS 21.41%
- Published 29.05.2013 14:29:06
- Last modified 11.04.2025 00:51:21
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a for...
CVE-2013-1915
- EPSS 4.85%
- Published 25.04.2013 23:55:01
- Last modified 11.04.2025 00:51:21
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference...
- EPSS 2.64%
- Published 19.04.2013 11:44:26
- Last modified 11.04.2025 00:51:21
The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of s...
CVE-2012-6129
- EPSS 2.68%
- Published 03.04.2013 00:55:01
- Last modified 11.04.2025 00:51:21
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol ...
- EPSS 0.4%
- Published 25.03.2013 21:55:02
- Last modified 11.04.2025 00:51:21
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the ...
CVE-2012-1568
- EPSS 0.05%
- Published 01.03.2013 05:40:15
- Last modified 11.04.2025 00:51:21
The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared libraries by a 32-bit executable file, which makes it easier for contex...
CVE-2012-3363
- EPSS 55.12%
- Published 13.02.2013 17:55:01
- Last modified 11.04.2025 00:51:21
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE...
CVE-2012-6075
- EPSS 5.97%
- Published 13.02.2013 01:55:03
- Last modified 11.04.2025 00:51:21
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly ex...
CVE-2013-0170
- EPSS 20.22%
- Published 08.02.2013 20:55:01
- Last modified 11.04.2025 00:51:21
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (c...
CVE-2012-5656
- EPSS 0.05%
- Published 18.01.2013 11:48:40
- Last modified 11.04.2025 00:51:21
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.