- EPSS 1.24%
- Veröffentlicht 12.12.2013 18:55:10
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in the getaddrinfo function in sysdeps/posix/getaddrinfo.c in GNU C Library (aka glibc or libc6) 2.18 and earlier allows remote attackers to cause a denial of service (crash) via a (1) hostname or (2) IP address that trigg...
CVE-2012-4412
- EPSS 18.7%
- Veröffentlicht 09.10.2013 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string, which triggers a heap-base...
CVE-2012-4424
- EPSS 0.61%
- Veröffentlicht 09.10.2013 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Stack-based buffer overflow in string/strcoll_l.c in the GNU C Library (aka glibc or libc6) 2.17 and earlier allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string that triggers a ...
CVE-2013-2207
- EPSS 0.07%
- Veröffentlicht 09.10.2013 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file sys...
CVE-2013-4237
- EPSS 1.42%
- Veröffentlicht 09.10.2013 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
sysdeps/posix/readdir_r.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allows context-dependent attackers to cause a denial of service (out-of-bounds write and crash) or possibly execute arbitrary code via a crafted (1) NTFS or (2) CIFS...
CVE-2013-4332
- EPSS 1.94%
- Veröffentlicht 09.10.2013 22:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple integer overflows in malloc/malloc.c in the GNU C Library (aka glibc or libc6) 2.18 and earlier allow context-dependent attackers to cause a denial of service (heap corruption) via a large value to the (1) pvalloc, (2) valloc, (3) posix_mema...
CVE-2013-4788
- EPSS 7.56%
- Veröffentlicht 04.10.2013 17:55:09
- Zuletzt bearbeitet 11.04.2025 00:51:21
The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control e...
CVE-2012-0864
- EPSS 2.11%
- Veröffentlicht 02.05.2013 14:55:05
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the vfprintf function in stdio-common/vfprintf.c in glibc 2.14 and other versions allows context-dependent attackers to bypass the FORTIFY_SOURCE protection mechanism, conduct format string attacks, and write to arbitrary memory v...
CVE-2009-5029
- EPSS 2.77%
- Veröffentlicht 02.05.2013 14:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Integer overflow in the __tzfile_read function in glibc before 2.15 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted timezone (TZ) file, as demonstrated using vsftpd.
- EPSS 0.73%
- Veröffentlicht 02.05.2013 14:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
The svc_run function in the RPC implementation in glibc before 2.15 allows remote attackers to cause a denial of service (CPU consumption) via a large number of RPC connections.