Show filters
298 Total Results
Displaying 71-80 of 298
Sort by:
Attacker Value
Unknown
CVE-2013-1896
Disclosure Date: July 10, 2013 (last updated October 05, 2023)
mod_dav.c in the Apache HTTP Server before 2.2.25 does not properly determine whether DAV is enabled for a URI, which allows remote attackers to cause a denial of service (segmentation fault) via a MERGE request in which the URI is configured for handling by the mod_dav_svn module, but a certain href attribute in XML data refers to a non-DAV URI.
0
Attacker Value
Unknown
CVE-2013-1362
Disclosure Date: July 09, 2013 (last updated October 05, 2023)
Incomplete blacklist vulnerability in nrpc.c in Nagios Remote Plug-In Executor (NRPE) before 2.14 might allow remote attackers to execute arbitrary shell commands via "$()" shell metacharacters, which are processed by bash.
0
Attacker Value
Unknown
CVE-2013-1690
Disclosure Date: June 26, 2013 (last updated October 22, 2024)
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.
0
Attacker Value
Unknown
CVE-2013-2064
Disclosure Date: June 15, 2013 (last updated October 05, 2023)
Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.
0
Attacker Value
Unknown
CVE-2013-1987
Disclosure Date: June 15, 2013 (last updated October 05, 2023)
Multiple integer overflows in X.org libXrender 0.9.7 and earlier allow X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the (1) XRenderQueryFilters, (2) XRenderQueryFormats, and (3) XRenderQueryPictIndexValues functions.
0
Attacker Value
Unknown
CVE-2013-1862
Disclosure Date: June 10, 2013 (last updated October 05, 2023)
mod_rewrite.c in the mod_rewrite module in the Apache HTTP Server 2.2.x before 2.2.25 writes data to a log file without sanitizing non-printable characters, which might allow remote attackers to execute arbitrary commands via an HTTP request containing an escape sequence for a terminal emulator.
0
Attacker Value
Unknown
CVE-2013-4074
Disclosure Date: June 09, 2013 (last updated October 05, 2023)
The dissect_capwap_data function in epan/dissectors/packet-capwap.c in the CAPWAP dissector in Wireshark 1.6.x before 1.6.16 and 1.8.x before 1.8.8 incorrectly uses a -1 data value to represent an error condition, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
0
Attacker Value
Unknown
CVE-2013-4077
Disclosure Date: June 09, 2013 (last updated October 05, 2023)
Array index error in the NBAP dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (application crash) via a crafted packet, related to nbap.cnf and packet-nbap.c.
0
Attacker Value
Unknown
CVE-2013-4079
Disclosure Date: June 09, 2013 (last updated October 05, 2023)
The dissect_schedule_message function in epan/dissectors/packet-gsm_cbch.c in the GSM CBCH dissector in Wireshark 1.8.x before 1.8.8 allows remote attackers to cause a denial of service (infinite loop and application hang) via a crafted packet.
0
Attacker Value
Unknown
CVE-2013-4078
Disclosure Date: June 09, 2013 (last updated October 05, 2023)
epan/dissectors/packet-rdp.c in the RDP dissector in Wireshark 1.8.x before 1.8.8 does not validate return values during checks for data availability, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
0