Search

Found 3,842 results in 367ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2013-3368 low 3.3 FIX debian debian bestpractical 13y ago bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictable name.
CVE-2011-4607 low 2.1 FIX debian debian putty 13y ago PuTTY 0.59 through 0.61 does not clear sensitive process memory when managing user replies that occur during keyboard-interactive authentication, which might allow local users to read login passwords…
CVE-2013-4959 low 2.1 FIX debian debian puppet 13y ago Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host na…
CVE-2013-4956 low 3.6 FIX debian debian puppetpuppetlabs 13y ago Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, installs modules with weak permissions if thos…
CVE-2013-4242 low 1.9 ubuntu ubuntususe susedebian debian gnupg 13y ago GnuPG before 1.4.14, and Libgcrypt before 1.5.3 as used in GnuPG 2.0.x and possibly other products, allows local users to obtain private RSA keys via a cache side-channel attack involving the L3 cach…
CVE-2013-4208 low 2.1 FIX debian debian puttysimon_tatham 13y ago The rsa_verify function in PuTTY before 0.63 (1) does not clear sensitive process memory after use and (2) does not free certain structures containing sensitive process memory, which might allow loca…
CVE-2013-5002 low 3.5 FIX debian debian phpmyadmin 13y ago phpMyAdmin Cross-site scripting (XSS) vulnerability via pageNumber value
CVE-2013-5001 low 3.5 FIX debian debian phpmyadmin 13y ago Cross-site scripting (XSS) vulnerability in libraries/plugins/transformations/abstract/TextLinkTransformationsPlugin.class.php in phpMyAdmin 4.0.x before 4.0.4.2 allows remote authenticated users to …
CVE-2013-4995 low 3.5 FIX debian debian phpmyadmin 13y ago Cross-site scripting (XSS) vulnerability in phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted SQL query t…
CVE-2013-3812 low 3.5 debian debianubuntu ubuntususe suse oraclemariadb 13y ago Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.31 and earlier and 5.6.11 and earlier allows remote authenticated users to affect availability via unknown vectors related …
CVE-2013-1868 critical 10.0 EXPFIX debian debian videolan 13y ago Multiple buffer overflows in VideoLAN VLC media player 2.0.4 and earlier allow remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to the (1) freetype…
CVE-2013-2870 critical 9.3 debian debian google 13y ago Use-after-free vulnerability in Google Chrome before 28.0.1500.71 allows remote servers to execute arbitrary code via crafted response traffic after a URL request.
CVE-2013-2096 low 2.1 FIX slesdebian debian openstack 13y ago OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by cr…
CVE-2013-2237 low 2.1 FIX linux-kerneldebian debian 13y ago The key_notify_policy_flush function in net/key/af_key.c in the Linux kernel before 3.9 does not initialize a certain structure member, which allows local users to obtain sensitive information from k…
CVE-2013-2234 low 2.1 FIX debian debian linux-kernel 13y ago The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obta…
CVE-2013-2164 low 2.1 FIX linux-kerneldebian debian rhel 13y ago The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfun…
CVE-2013-3742 low 3.5 FIX debian debian phpmyadmin 13y ago Cross-site scripting (XSS) vulnerability in view_create.php (aka the Create View page) in phpMyAdmin 4.x before 4.0.3 allows remote authenticated users to inject arbitrary web script or HTML via an i…
CVE-2013-2168 low 1.9 FIX debian debiansuse suse freedesktop 13y ago The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of s…
CVE-2013-1961 critical 9.3 FIX debian debian remotesensing 13y ago Stack-based buffer overflow in the t2p_write_pdf_page function in tiff2pdf in libtiff before 4.0.3 allows remote attackers to cause a denial of service (application crash) via a crafted image length …
CVE-2013-1960 critical 9.3 FIX debian debian remotesensing 13y ago Heap-based buffer overflow in the t2p_process_jpeg_strip function in tiff2pdf in libtiff 4.0.3 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary …
CVE-2011-4098 low 1.9 FIX debian debian linux-kernel 13y ago The fallocate implementation in the GFS2 filesystem in the Linux kernel before 3.2 relies on the page cache, which might allow local users to cause a denial of service by preallocating blocks in cert…
CVE-2013-2148 low 2.1 FIX slesdebian debian linux-kernel 13y ago The fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive i…
CVE-2013-2147 low 2.1 FIX suse susedebian debian linux-kernel 13y ago The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to…
CVE-2013-2141 low 2.1 FIX debian debian linux-kernel 13y ago The do_tkill function in kernel/signal.c in the Linux kernel before 3.8.9 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via…
CVE-2013-2863 critical 10.0 debian debian google 13y ago Google Chrome before 27.0.1453.110 does not properly handle SSL sockets, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vecto…
CVE-2013-2006 low 2.1 FIX debian debian openstack 13y ago OpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in plaintext, which allows local users to obtain sensitive by readin…
CVE-2013-1977 low 2.1 FIX debian debian openstack 13y ago OpenStack devstack uses world-readable permissions for keystone.conf, which allows local users to obtain sensitive information such as the LDAP password and admin_token secret by reading the file.
CVE-2013-1952 low 1.9 FIX debian debian 13y ago Xen 4.x, when using Intel VT-d for a bus mastering capable PCI device, does not properly check the source when accessing a bridge device's interrupt remapping table entries for MSI interrupts, which …
CVE-2013-1940 low 2.1 FIX ubuntu ubuntudebian debian x 13y ago X.Org X server before 1.13.4 and 1.4.x before 1.14.1 does not properly restrict access to input events when adding a new hot-plug device, which might allow physically proximate attackers to obtain se…
CVE-2013-1922 low 3.3 FIX debian debian 13y ago qemu-nbd in QEMU, as used in Xen 4.2.x, determines the format of a raw disk image based on the header, which allows local guest OS administrators to read arbitrary files on the host by modifying the …
CVE-2013-1917 low 1.9 FIX debian debian 13y ago Xen 3.1 through 4.x, when running 64-bit hosts on Intel CPUs, does not clear the NT flag when using an IRET after a SYSENTER instruction, which allows PV guest users to cause a denial of service (hyp…
CVE-2013-1897 low 2.6 FIX debian debian fedoraproject 13y ago The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anony…
CVE-2013-1959 low 4.7 EXPFIX debian debian linux-kernel 13y ago kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a …
CVE-2013-1845 low 2.1 FIX suse susedebian debian apache 13y ago The mod_dav_svn Apache HTTPD server module in Subversion 1.6.x before 1.6.21 and 1.7.0 through 1.7.8 allows remote authenticated users to cause a denial of service (memory consumption) by (1) setting…
CVE-2013-1958 low 1.9 FIX debian debian linux-kernel 13y ago The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.8.6 does not properly enforce capability requirements for controlling the PID value associated with a UNIX domain socket, w…
CVE-2013-1956 low 2.1 FIX linux-kerneldebian debian 13y ago The create_user_ns function in kernel/user_namespace.c in the Linux kernel before 3.8.6 does not check whether a chroot directory exists that differs from the namespace root directory, which allows l…
CVE-2012-6140 low 1.9 FIX debian debian google 13y ago pam_google_authenticator.c in the PAM module in Google Authenticator before 1.0 requires user-readable permissions for the secret file, which allows local users to bypass intended access restrictions…
CVE-2013-2384 critical 10.0 FIX debian debian oraclesun 13y ago Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allow…
CVE-2013-2383 critical 10.0 FIX debian debian oraclesun 13y ago Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allow…
CVE-2013-1569 critical 10.0 FIX debian debian oraclesun 13y ago Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allow…
CVE-2012-6120 low 2.1 FIX debian debian redhat 13y ago Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.
CVE-2012-5635 low 2.1 FIX debian debian glusterredhat 13y ago The GlusterFS functionality in Red Hat Storage Management Console 2.0, Native Client, and Server 2.0 allows local users to overwrite arbitrary files via a symlink attack on multiple temporary files c…
CVE-2013-1840 low 3.5 FIX debian debian openstackamazon 13y ago OpenStack Glance is vulnerable to Exposure of Sensitive Information
CVE-2013-2636 low 1.9 FIX debian debian linux-kernel 13y ago net/bridge/br_mdb.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.
CVE-2013-2635 low 1.9 FIX linux-kerneldebian debian 13y ago The rtnl_fill_ifinfo function in net/core/rtnetlink.c in the Linux kernel before 3.8.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from ke…
CVE-2013-2634 low 1.9 FIX linux-kerneldebian debian 13y ago net/dcb/dcbnl.c in the Linux kernel before 3.8.4 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
CVE-2013-0914 low 3.6 FIX linux-kerneldebian debian 13y ago The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to …
CVE-2013-1427 low 1.9 FIX debian debian lighttpd 13y ago The configuration file for the FastCGI PHP support for lighttpd before 1.4.28 on Debian GNU/Linux creates a socket file with a predictable name in /tmp, which allows local users to hijack the PHP con…
CVE-2013-1640 critical 9.0 FIX ubuntu ubuntudebian debian puppet 13y ago The (1) template and (2) inline_template functions in the master server in Puppet before 2.6.18, 2.7.x before 2.7.21, and 3.1.x before 3.1.1, and Puppet Enterprise before 1.2.7 and 2.7.x before 2.7.2…
CVE-2013-1766 low 3.6 FIX debian debian redhat 13y ago libvirt 1.0.2 and earlier sets the group owner to kvm for device files, which allows local users to write to these files via unspecified vectors.
CVE-2013-0251 critical 10.0 FIX debian debian debian 13y ago Stack-based buffer overflow in llogincircuit.cc in latd 1.25 through 1.30 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long strin…
CVE-2013-0248 low 3.3 FIX debian debian apache 13y ago Incorrect Default Permissions in Apache Commons FileUpload
CVE-2013-2548 low 2.1 FIX linux-kerneldebian debian 13y ago The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect length value during a copy operation,…
CVE-2013-2547 low 2.1 FIX linux-kerneldebian debian 13y ago The crypto_report_one function in crypto/crypto_user.c in the report API in the crypto user configuration API in the Linux kernel through 3.8.2 does not initialize certain structure members, which al…
CVE-2013-2546 low 2.1 FIX sles linux-kerneldebian debian 13y ago The report API in the crypto user configuration API in the Linux kernel through 3.8.2 uses an incorrect C library function for copying strings, which allows local users to obtain sensitive informatio…
CVE-2012-6549 low 1.9 FIX debian debian linux-kernel 13y ago The isofs_export_encode_fh function in fs/isofs/export.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from k…
CVE-2012-6548 low 1.9 FIX linux-kerneldebian debian rhel 13y ago The udf_encode_fh function in fs/udf/namei.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel heap m…
CVE-2012-6547 low 1.9 FIX debian debian linux-kernel 13y ago The __tun_chr_ioctl function in drivers/net/tun.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack me…
CVE-2012-6546 low 1.9 FIX linux-kerneldebian debian rhel 13y ago The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted applicati…
CVE-2012-6545 low 1.9 FIX linux-kerneldebian debian rhel 13y ago The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a c…
CVE-2012-6544 low 1.9 FIX linux-kerneldebian debian rhel 13y ago The Bluetooth protocol stack in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a cr…
CVE-2012-6543 low 1.9 FIX linux-kerneldebian debian 13y ago The l2tp_ip6_getname function in net/l2tp/l2tp_ip6.c in the Linux kernel before 3.6 does not initialize a certain structure member, which allows local users to obtain sensitive information from kerne…
CVE-2012-6542 low 1.9 FIX debian debian linux-kernel rhel 13y ago The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from ke…
CVE-2012-6541 low 1.9 FIX debian debian linux-kernel 13y ago The ccid3_hc_tx_getsockopt function in net/dccp/ccids/ccid3.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from ker…
CVE-2012-6540 low 1.9 FIX linux-kerneldebian debian 13y ago The do_ip_vs_get_ctl function in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 3.6 does not initialize a certain structure for IP_VS_SO_GET_TIMEOUT commands, which allows local users to o…
CVE-2012-6539 low 1.9 FIX debian debian linux-kernel 13y ago The dev_ifconf function in net/socket.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a…
CVE-2012-6538 low 1.9 FIX linux-kerneldebian debian rhel 13y ago The copy_to_user_auth function in net/xfrm/xfrm_user.c in the Linux kernel before 3.6 uses an incorrect C library function for copying a string, which allows local users to obtain sensitive informati…
CVE-2012-6537 low 1.9 FIX linux-kerneldebian debian rhel 13y ago net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN…
CVE-2012-6536 low 2.1 FIX debian debian linux-kernel 13y ago net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not verify that the actual Netlink message length is consistent with a certain header field, which allows local users to obtain sensitive info…
CVE-2013-1049 critical 10.0 FIX debian debian debian 13y ago Buffer overflow in the RFC1413 (ident) client in cfingerd 1.4.3-3 allows remote IDENT servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted response.
CVE-2013-2484 low 3.3 FIX suse susedebian debian wireshark 13y ago The CIMD dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-2483 low 3.3 FIX suse susedebian debian wireshark 13y ago The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide…
CVE-2013-2481 low 2.9 FIX suse susedebian debian wireshark 13y ago Integer signedness error in the dissect_mount_dirpath_call function in epan/dissectors/packet-mount.c in the Mount dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6, when nfs_file_nam…
CVE-2013-2480 low 3.3 FIX suse susedebian debian wireshark 13y ago The RTPS and RTPS2 dissectors in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allow remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-2479 low 3.3 FIX suse susedebian debian wireshark 13y ago The dissect_mpls_echo_tlv_dd_map function in epan/dissectors/packet-mpls-echo.c in the MPLS Echo dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (infini…
CVE-2013-2478 low 3.3 FIX suse susedebian debian wireshark 13y ago The dissect_server_info function in epan/dissectors/packet-ms-mms.c in the MS-MMS dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 does not properly manage string lengths, which allo…
CVE-2013-2477 low 3.3 FIX suse susedebian debian wireshark 13y ago The CSN.1 dissector in Wireshark 1.8.x before 1.8.6 does not properly manage function pointers, which allows remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-2475 low 3.3 FIX suse susedebian debian wireshark 13y ago The TCP dissector in Wireshark 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-0200 low 1.9 FIX sles rheldebian debian hp 13y ago HP Linux Imaging and Printing (HPLIP) through 3.12.4 allows local users to overwrite arbitrary files via a symlink attack on the (1) /tmp/hpcupsfilterc_#.bmp, (2) /tmp/hpcupsfilterk_#.bmp, (3) /tmp/h…
CVE-2013-0349 low 1.9 FIX linux-kerneldebian debian 14y ago The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel before 3.7.6 does not properly copy a certain name field, which allows local users to obtain sensitive information from ke…
CVE-2013-0343 low 3.2 FIX linux-kerneldebian debian 14y ago The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.8 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attacke…
CVE-2013-0219 low 3.7 FIX sles rheldebian debian fedoraproject 14y ago System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a …
CVE-2013-0783 critical 9.3 suse suseubuntu ubuntu rhel mozilla 14y ago Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17.0.3, and SeaMonkey…
CVE-2013-0782 critical 9.3 suse suseubuntu ubuntu rhel mozilla 14y ago Heap-based buffer overflow in the nsSaveAsCharset::DoCharsetConversion function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before …
CVE-2013-0780 critical 9.3 suse suseubuntu ubuntu rhel mozilla 14y ago Use-after-free vulnerability in the nsOverflowContinuationTracker::Finish function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x befo…
CVE-2013-0775 critical 9.3 suse suseubuntu ubuntu rhel mozilla 14y ago Use-after-free vulnerability in the nsImageLoadingContent::OnStopContainer function in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x bef…
CVE-2013-0773 critical 9.3 suse suseubuntu ubuntudebian debian mozilla 14y ago The Chrome Object Wrapper (COW) and System Only Wrapper (SOW) implementations in Mozilla Firefox before 19.0, Firefox ESR 17.x before 17.0.3, Thunderbird before 17.0.3, Thunderbird ESR 17.x before 17…
CVE-2013-0160 low 3.1 EXPFIX debian debian linux-kernel 14y ago The Linux kernel through 3.7.9 allows local users to obtain sensitive information about keystroke timing by using the inotify API on the /dev/ptmx device.
CVE-2012-4530 low 3.1 EXPFIX linux-kerneldebian debian 14y ago The load_script function in fs/binfmt_script.c in the Linux kernel before 3.7.2 does not properly handle recursion, which allows local users to obtain sensitive information from kernel stack memory v…
CVE-2013-0274 low 2.9 FIX debian debian pidgin 14y ago upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging ac…
CVE-2012-5564 low 3.3 debian debian google 14y ago android-tools 4.1.1 in Android Debug Bridge (ADB) allows local users to overwrite arbitrary files via a symlink attack on /tmp/adb.log.
CVE-2012-3363 critical 9.1 10.0 EXP fedora fedoradebian debian zend 14y ago Zend Framework XXE Vulnerability
CVE-2013-0241 low 2.1 FIX ubuntu ubuntu rheldebian debian 14y ago The QXL display driver in QXL Virtual GPU 0.1.0 allows local users to cause a denial of service (guest crash or hang) via a SPICE connection that prevents other threads from obtaining the qemu_mutex …
CVE-2012-6075 critical 9.3 FIX ubuntu ubuntu rhelsuse suse qemuredhat 14y ago Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a…
CVE-2013-0277 critical 10.0 FIX debian debian rubyonrails 14y ago ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +seria…
CVE-2013-0169 low 2.6 FIX debian debian openssloraclepolarssl 14y ago The TLS protocol 1.1 and 1.2 and the DTLS protocol 1.0 and 1.2, as used in OpenSSL, OpenJDK, PolarSSL, and other products, do not properly consider timing side-channel attacks on a MAC check requirem…
CVE-2013-1590 low 2.9 FIX debian debian wireshark 14y ago Buffer overflow in the NTLMSSP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote attackers to cause a denial of service (application crash) via a malformed packet.
CVE-2013-1589 low 2.9 FIX debian debian wireshark 14y ago Double free vulnerability in epan/proto.c in the dissection engine in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allows remote attackers to cause a denial of service (application crash) via…
CVE-2013-1588 low 2.9 FIX debian debian wireshark 14y ago Multiple buffer overflows in the dissect_pft_fec_detailed function in the DCP-ETSI dissector in epan/dissectors/packet-dcp-etsi.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 allow remote …
CVE-2013-1587 low 2.9 FIX debian debian wireshark 14y ago The dissect_rohc_ir_packet function in epan/dissectors/packet-rohc.c in the ROHC dissector in Wireshark 1.8.x before 1.8.5 does not properly handle unknown profiles, which allows remote attackers to …