Show filters
86 Total Results
Displaying 21-30 of 86
Sort by:
Attacker Value
Unknown

CVE-2013-6712

Disclosure Date: November 28, 2013 (last updated October 05, 2023)
The scan function in ext/date/lib/parse_iso_intervals.c in PHP through 5.5.6 does not properly restrict creation of DateInterval objects, which might allow remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted interval specification.
0
Attacker Value
Unknown

CVE-2013-1058

Disclosure Date: November 23, 2013 (last updated October 05, 2023)
maas-import-pxe-files in MAAS before 13.10 does not verify the integrity of downloaded files, which allows remote attackers to modify these files via a man-in-the-middle (MITM) attack.
0
Attacker Value
Unknown

CVE-2013-6858

Disclosure Date: November 23, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in OpenStack Dashboard (Horizon) 2013.2 and earlier allow local users to inject arbitrary web script or HTML via an instance name to (1) "Volumes" or (2) "Network Topology" page.
0
Attacker Value
Unknown

CVE-2013-6629

Disclosure Date: November 19, 2013 (last updated October 05, 2023)
The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive information from uninitialized memory locations via a crafted JPEG image.
0
Attacker Value
Unknown

CVE-2013-1057

Disclosure Date: November 18, 2013 (last updated October 05, 2023)
Untrusted search path vulnerability in maas-import-pxe-files in MAAS before 13.10 allows local users to execute arbitrary code via a Trojan horse import_pxe_files configuration file in the current working directory.
0
Attacker Value
Unknown

CVE-2013-4475

Disclosure Date: November 13, 2013 (last updated October 05, 2023)
Samba 3.2.x through 3.6.x before 3.6.20, 4.0.x before 4.0.11, and 4.1.x before 4.1.1, when vfs_streams_depot or vfs_streams_xattr is enabled, allows remote attackers to bypass intended file restrictions by leveraging ACL differences between a file and an associated alternate data stream (ADS).
0
Attacker Value
Unknown

CVE-2013-4402

Disclosure Date: October 28, 2013 (last updated October 05, 2023)
The compressed packet parser in GnuPG 1.4.x before 1.4.15 and 2.0.x before 2.0.22 allows remote attackers to cause a denial of service (infinite recursion) via a crafted OpenPGP message.
0
Attacker Value
Unknown

CVE-2013-1056

Disclosure Date: October 28, 2013 (last updated October 05, 2023)
X.org X server 1.13.3 and earlier, when not run as root, allows local users to cause a denial of service (crash) or possibly gain privileges via vectors involving cached xkb files.
0
Attacker Value
Unknown

CVE-2013-4428

Disclosure Date: October 27, 2013 (last updated October 05, 2023)
OpenStack Image Registry and Delivery Service (Glance) Folsom, Grizzly before 2013.1.4, and Havana before 2013.2, when the download_image policy is configured, does not properly restrict access to cached images, which allows remote authenticated users to read otherwise restricted images via an image UUID.
0
Attacker Value
Unknown

CVE-2013-1067

Disclosure Date: October 25, 2013 (last updated October 05, 2023)
Apport 2.12.5 and earlier uses weak permissions for core dump files created by setuid binaries, which allows local users to obtain sensitive information by reading the file.
0