Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 53 269

Количество 53 269

redhat логотип

CVE-2013-0331

больше 13 лет назад

Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to cause a denial of service via a crafted payload.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2013-0330

больше 13 лет назад

Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to build arbitrary jobs via unknown attack vectors.

CVSS2: 3.5
EPSS: Низкий
redhat логотип

CVE-2013-0329

больше 13 лет назад

Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to bypass the CSRF protection mechanism via unknown attack vectors.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2013-0328

больше 13 лет назад

Cross-site scripting (XSS) vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2013-0327

больше 13 лет назад

Cross-site request forgery (CSRF) vulnerability in Jenkins master in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to hijack the authentication of users via unknown vectors.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2013-0315

больше 13 лет назад

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted external XML entity in an XML document, aka an XML Entity Expansion (XEE) attack.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2013-0314

больше 13 лет назад

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, which allows remote attackers to modify site contents, remove the site, or alter the access controls for portlets.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2013-0313

больше 13 лет назад

The evm_update_evmxattr function in security/integrity/evm/evm_crypto.c in the Linux kernel before 3.7.5, when the Extended Verification Module (EVM) is enabled, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an attempted removexattr operation on an inode of a sockfs filesystem.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2013-0312

больше 13 лет назад

389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2013-0311

больше 13 лет назад

The translate_desc function in drivers/vhost/vhost.c in the Linux kernel before 3.7 does not properly handle cross-region descriptors, which allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges.

CVSS2: 6.5
EPSS: Низкий
redhat логотип

CVE-2013-0310

больше 13 лет назад

The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.

CVSS2: 4.4
EPSS: Низкий
redhat логотип

CVE-2013-0309

больше 13 лет назад

arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when transparent huge pages are used, does not properly support PROT_NONE memory regions, which allows local users to cause a denial of service (system crash) via a crafted application.

CVSS2: 4.7
EPSS: Низкий
redhat логотип

CVE-2013-0308

больше 13 лет назад

The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2013-0306

больше 13 лет назад

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2013-0305

больше 13 лет назад

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
EPSS: Низкий
redhat логотип

CVE-2013-0293

больше 13 лет назад

oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation

CVSS2: 6.2
EPSS: Низкий
redhat логотип

CVE-2013-0292

больше 13 лет назад

The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.

CVSS2: 6.9
EPSS: Низкий
redhat логотип

CVE-2013-0290

больше 13 лет назад

The __skb_recv_datagram function in net/core/datagram.c in the Linux kernel before 3.8 does not properly handle the MSG_PEEK flag with zero-length data, which allows local users to cause a denial of service (infinite loop and system hang) via a crafted application.

CVSS2: 4.9
EPSS: Низкий
redhat логотип

CVE-2013-0288

больше 13 лет назад

nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2013-0287

больше 13 лет назад

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

CVSS2: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2013-0331

Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to cause a denial of service via a crafted payload.

CVSS2: 4
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0330

Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote authenticated users with write access to build arbitrary jobs via unknown attack vectors.

CVSS2: 3.5
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0329

Unspecified vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to bypass the CSRF protection mechanism via unknown attack vectors.

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0328

Cross-site scripting (XSS) vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0327

Cross-site request forgery (CSRF) vulnerability in Jenkins master in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to hijack the authentication of users via unknown vectors.

CVSS2: 4.3
3%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0315

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 allows remote attackers to read arbitrary files via a crafted external XML entity in an XML document, aka an XML Entity Expansion (XEE) attack.

CVSS2: 5
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0314

The GateIn Portal export/import gadget in JBoss Enterprise Portal Platform 5.2.2 does not properly check authentication when importing Zip files, which allows remote attackers to modify site contents, remove the site, or alter the access controls for portlets.

CVSS2: 7.5
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0313

The evm_update_evmxattr function in security/integrity/evm/evm_crypto.c in the Linux kernel before 3.7.5, when the Extended Verification Module (EVM) is enabled, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an attempted removexattr operation on an inode of a sockfs filesystem.

CVSS2: 4
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0312

389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence.

CVSS2: 5
3%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0311

The translate_desc function in drivers/vhost/vhost.c in the Linux kernel before 3.7 does not properly handle cross-region descriptors, which allows guest OS users to obtain host OS privileges by leveraging KVM guest OS privileges.

CVSS2: 6.5
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0310

The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.

CVSS2: 4.4
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0309

arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when transparent huge pages are used, does not properly support PROT_NONE memory regions, which allows local users to cause a denial of service (system crash) via a crafted application.

CVSS2: 4.7
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0308

The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0306

The form library in Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 allows remote attackers to bypass intended resource limits for formsets and cause a denial of service (memory consumption) or trigger server errors via a modified max_num parameter.

CVSS2: 5
3%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0305

The administrative interface for Django 1.3.x before 1.3.6, 1.4.x before 1.4.4, and 1.5 before release candidate 2 does not check permissions for the history view, which allows remote authenticated administrators to obtain sensitive object history information.

CVSS2: 4
2%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0293

oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation

CVSS2: 6.2
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0292

The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.

CVSS2: 6.9
1%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0290

The __skb_recv_datagram function in net/core/datagram.c in the Linux kernel before 3.8 does not properly handle the MSG_PEEK flag with zero-length data, which allows local users to cause a denial of service (infinite loop and system hang) via a crafted application.

CVSS2: 4.9
0%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0288

nss-pam-ldapd before 0.7.18 and 0.8.x before 0.8.11 allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code by performing a name lookup on an application with a large number of open file descriptors, which triggers a stack-based buffer overflow related to incorrect use of the FD_SET macro.

CVSS2: 5.1
4%
Низкий
больше 13 лет назад
redhat логотип
CVE-2013-0287

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authenticated users to bypass intended access restrictions.

CVSS2: 4.9
2%
Низкий
больше 13 лет назад

Уязвимостей на страницу