Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 251

Количество 53 251

redhat логотип

CVE-2013-2124

около 13 лет назад

Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2013-2121

около 13 лет назад

Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.

CVSS2: 6
EPSS: Средний
redhat логотип

CVE-2013-2120

около 13 лет назад

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.

CVSS2: 1.2
EPSS: Низкий
redhat логотип

CVE-2013-2119

около 13 лет назад

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.

CVSS2: 4.6
EPSS: Низкий
redhat логотип

CVE-2013-2116

около 13 лет назад

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2013-2115

около 13 лет назад

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.

CVSS2: 6.8
EPSS: Высокий
redhat логотип

CVE-2013-2113

около 13 лет назад

The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.

CVSS2: 3.5
EPSS: Средний
redhat логотип

CVE-2013-2112

около 13 лет назад

The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2013-2111

около 13 лет назад

The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid APPEND parameters.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2013-2110

около 13 лет назад

Heap-based buffer overflow in the php_quot_print_encode function in ext/standard/quot_print.c in PHP before 5.3.26 and 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted argument to the quoted_printable_encode function.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2013-2104

около 13 лет назад

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2013-2103

около 11 лет назад

OpenShift cartridge allows remote URL retrieval

CVSS2: 5.5
EPSS: Низкий
redhat логотип

CVE-2013-2102

почти 13 лет назад

The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.

CVSS2: 3.3
EPSS: Низкий
redhat логотип

CVE-2013-2101

около 12 лет назад

Katello has multiple XSS issues in various entities

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2013-2099

около 13 лет назад

Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2013-2096

около 13 лет назад

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2013-2095

около 11 лет назад

rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2013-2094

около 13 лет назад

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

CVSS2: 7.2
EPSS: Средний
redhat логотип

CVE-2013-2088

около 13 лет назад

contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.

CVSS2: 4.6
EPSS: Средний
redhat логотип

CVE-2013-2078

около 13 лет назад

Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.

CVSS2: 5.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2013-2124

Double free vulnerability in inspect-fs.c in LibguestFS 1.20.x before 1.20.7, 1.21.x, 1.22.0, and 1.23.0 allows remote attackers to cause a denial of service (crash) via empty guest files.

CVSS2: 4.3
3%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2121

Eval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create bookmarks to execute arbitrary code via a controller name attribute.

CVSS2: 6
25%
Средний
около 13 лет назад
redhat логотип
CVE-2013-2120

The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass authentication via a brute-force attack.

CVSS2: 1.2
1%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2119

Phusion Passenger gem before 3.0.21 and 4.0.x before 4.0.5 for Ruby allows local users to cause a denial of service (prevent application start) or gain privileges by pre-creating a temporary "config" file in a directory with a predictable name in /tmp/ before it is used by the gem.

CVSS2: 4.6
0%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2116

The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.

CVSS2: 5
4%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2115

Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) A tag. NOTE: this issue is due to an incomplete fix for CVE-2013-1966.

CVSS2: 6.8
73%
Высокий
около 13 лет назад
redhat логотип
CVE-2013-2113

The create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to create or edit other users to gain privileges by (1) changing the admin flag or (2) assigning an arbitrary role.

CVSS2: 3.5
21%
Средний
около 13 лет назад
redhat логотип
CVE-2013-2112

The svnserve server in Subversion before 1.6.23 and 1.7.x before 1.7.10 allows remote attackers to cause a denial of service (exit) by aborting a connection.

CVSS2: 2.6
4%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2111

The IMAP functionality in Dovecot before 2.2.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via invalid APPEND parameters.

CVSS2: 4
2%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2110

Heap-based buffer overflow in the php_quot_print_encode function in ext/standard/quot_print.c in PHP before 5.3.26 and 5.4.x before 5.4.16 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted argument to the quoted_printable_encode function.

CVSS2: 6.8
7%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2104

python-keystoneclient before 0.2.4, as used in OpenStack Keystone (Folsom), does not properly check expiry for PKI tokens, which allows remote authenticated users to (1) retain use of a token after it has expired, or (2) use a revoked token once it expires.

CVSS2: 2.6
2%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2103

OpenShift cartridge allows remote URL retrieval

CVSS2: 5.5
1%
Низкий
около 11 лет назад
redhat логотип
CVE-2013-2102

The default configuration of Red Hat JBoss Portal before 6.1.0 enables the JGroups diagnostics service with no authentication when a JGroups channel is started, which allows remote attackers to obtain sensitive information (diagnostics) by accessing the service.

CVSS2: 3.3
1%
Низкий
почти 13 лет назад
redhat логотип
CVE-2013-2101

Katello has multiple XSS issues in various entities

CVSS2: 4
1%
Низкий
около 12 лет назад
redhat логотип
CVE-2013-2099

Algorithmic complexity vulnerability in the ssl.match_hostname function in Python 3.2.x, 3.3.x, and earlier, and unspecified versions of python-backports-ssl_match_hostname as used for older Python versions, allows remote attackers to cause a denial of service (CPU consumption) via multiple wildcard characters in the common name in a certificate.

CVSS2: 2.6
5%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2096

OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by creating an image with a large virtual size that does not contain a large amount of data.

CVSS2: 4
0%
Низкий
около 13 лет назад
redhat логотип
CVE-2013-2095

rubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection

CVSS2: 6.5
2%
Низкий
около 11 лет назад
redhat логотип
CVE-2013-2094

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

CVSS2: 7.2
48%
Средний
около 13 лет назад
redhat логотип
CVE-2013-2088

contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute arbitrary commands via shell metacharacters in a filename.

CVSS2: 4.6
31%
Средний
около 13 лет назад
redhat логотип
CVE-2013-2078

Xen 4.0.2 through 4.0.4, 4.1.x, and 4.2.x allows local PV guest users to cause a denial of service (hypervisor crash) via certain bit combinations to the XSETBV instruction.

CVSS2: 5.7
0%
Низкий
около 13 лет назад

Уязвимостей на страницу