Show filters
433 Total Results
Displaying 291-300 of 433
Sort by:
Attacker Value
Unknown

CVE-2013-1418

Disclosure Date: November 18, 2013 (last updated October 05, 2023)
The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted request.
0
Attacker Value
Unknown

CVE-2013-6621

Disclosure Date: November 13, 2013 (last updated October 05, 2023)
Use-after-free vulnerability in Google Chrome before 31.0.1650.48 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the x-webkit-speech attribute in a text INPUT element.
0
Attacker Value
Unknown

CVE-2013-4508

Disclosure Date: November 08, 2013 (last updated November 25, 2024)
lighttpd before 1.4.34, when SNI is enabled, configures weak SSL ciphers, which makes it easier for remote attackers to hijack sessions by inserting packets into the client-server data stream or obtain sensitive information by sniffing the network.
Attacker Value
Unknown

CVE-2013-4365

Disclosure Date: October 17, 2013 (last updated October 05, 2023)
Heap-based buffer overflow in the fcgid_header_bucket_read function in fcgid_bucket.c in the mod_fcgid module before 2.3.9 for the Apache HTTP Server allows remote attackers to have an unspecified impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2013-4389

Disclosure Date: October 17, 2013 (last updated October 05, 2023)
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
0
Attacker Value
Unknown

CVE-2013-2927

Disclosure Date: October 16, 2013 (last updated October 05, 2023)
Use-after-free vulnerability in the HTMLFormElement::prepareForSubmission function in core/html/HTMLFormElement.cpp in Blink, as used in Google Chrome before 30.0.1599.101, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to submission for FORM elements.
0
Attacker Value
Unknown

CVE-2013-2919

Disclosure Date: October 02, 2013 (last updated October 05, 2023)
Google V8, as used in Google Chrome before 30.0.1599.66, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2013-5589

Disclosure Date: August 29, 2013 (last updated October 05, 2023)
SQL injection vulnerability in cacti/host.php in Cacti 0.8.8b and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2013-4852

Disclosure Date: August 19, 2013 (last updated October 05, 2023)
Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code in certain applications that use PuTTY via a negative size value in an RSA key signature during the SSH handshake, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2013-4242

Disclosure Date: August 19, 2013 (last updated October 05, 2023)
GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cache, aka Flush+Reload.
0