Show filters
199 Total Results
Displaying 111-120 of 199
Sort by:
Attacker Value
Unknown

CVE-2013-4397

Disclosure Date: October 17, 2013 (last updated October 05, 2023)
Multiple integer overflows in the th_read function in lib/block.c in libtar before 1.2.20 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) name or (2) link in an archive, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2013-3567

Disclosure Date: August 19, 2013 (last updated October 05, 2023)
Puppet 2.7.x before 2.7.22 and 3.2.x before 3.2.2, and Puppet Enterprise before 2.8.2, deserializes untrusted YAML, which allows remote attackers to instantiate arbitrary Ruby classes and execute arbitrary code via a crafted REST API call.
0
Attacker Value
Unknown

CVE-2013-4242

Disclosure Date: August 19, 2013 (last updated October 05, 2023)
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
0
Attacker Value
Unknown

CVE-2013-2132

Disclosure Date: August 15, 2013 (last updated October 05, 2023)
bson/_cbsonmodule.c in the mongo-python-driver (aka. pymongo) before 2.5.2, as used in MongoDB, allows context-dependent attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to decoding of an "invalid DBRef."
0
Attacker Value
Unknown

CVE-2013-2064

Disclosure Date: June 15, 2013 (last updated October 05, 2023)
Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.
0
Attacker Value
Unknown

CVE-2013-1927

Disclosure Date: April 29, 2013 (last updated October 05, 2023)
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 allows remote attackers to execute arbitrary code via a crafted file that validates as both a GIF and a Java JAR file, aka "GIFAR."
0
Attacker Value
Unknown

CVE-2013-1926

Disclosure Date: April 29, 2013 (last updated October 05, 2023)
The IcedTea-Web plugin before 1.2.3 and 1.3.x before 1.3.2 uses the same class loader for applets with the same codebase path but from different domains, which allows remote attackers to obtain sensitive information or possibly alter other applets via a crafted applet.
0
Attacker Value
Unknown

CVE-2012-6129

Disclosure Date: April 03, 2013 (last updated October 05, 2023)
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."
0
Attacker Value
Unknown

CVE-2013-1653

Disclosure Date: March 20, 2013 (last updated October 05, 2023)
Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2, when listening for incoming connections is enabled and allowing access to the "run" REST endpoint is allowed, allows remote authenticated users to execute arbitrary code via a crafted HTTP request.
0
Attacker Value
Unknown

CVE-2013-1855

Disclosure Date: March 19, 2013 (last updated October 05, 2023)
The sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.
0