Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 337

Количество 77 337

ubuntu логотип

CVE-2014-0001

больше 12 лет назад

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-NNN1

больше 12 лет назад

The mysql-5.5 package misses the patches applied previous in Debian's mysql-5.1 to drop the database "test" and the permissions that allow anonymous access, without a password, from localhost to the "test" database and any databases starting with "test_". This update reintroduces these patches for the mysql-5.5 package.

EPSS: Низкий
ubuntu логотип

CVE-2013-7491

почти 6 лет назад

An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack gets reallocated.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2013-7490

почти 6 лет назад

An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2013-7489

около 6 лет назад

The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.

CVSS3: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-7488

больше 6 лет назад

perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-7484

почти 7 лет назад

Zabbix before 5.0 represents passwords in the users table with unsalted MD5.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-7470

больше 7 лет назад

cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2013-7469

больше 7 лет назад

Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-7464

около 8 лет назад

In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2013-7459

больше 9 лет назад

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2013-7458

около 10 лет назад

linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2013-7457

около 10 лет назад

Unspecified vulnerability in the Qualcomm components in Android before 2016-07-05 allows attackers to gain privileges via a crafted application.

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2013-7456

около 10 лет назад

gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted image that is mishandled by the imagescale function.

CVSS3: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2013-7455

больше 10 лет назад

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2013-7454

больше 9 лет назад

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2013-7453

больше 9 лет назад

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2013-7452

больше 9 лет назад

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2013-7451

больше 9 лет назад

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2013-7449

больше 10 лет назад

The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2014-0001

Buffer overflow in client/mysql.cc in Oracle MySQL and MariaDB before 5.5.35 allows remote database servers to cause a denial of service (crash) and possibly execute arbitrary code via a long server version string.

CVSS2: 7.5
6%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-NNN1

The mysql-5.5 package misses the patches applied previous in Debian's mysql-5.1 to drop the database "test" and the permissions that allow anonymous access, without a password, from localhost to the "test" database and any databases starting with "test_". This update reintroduces these patches for the mysql-5.5 package.

больше 12 лет назад
ubuntu логотип
CVE-2013-7491

An issue was discovered in the DBI module before 1.628 for Perl. Stack corruption occurs when a user-defined function requires a non-trivial amount of memory and the Perl stack gets reallocated.

CVSS3: 5.3
3%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2013-7490

An issue was discovered in the DBI module before 1.632 for Perl. Using many arguments to methods for Callbacks may lead to memory corruption.

CVSS3: 5.3
3%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2013-7489

The Beaker library through 1.11.0 for Python is affected by deserialization of untrusted data, which could lead to arbitrary code execution.

CVSS3: 6.8
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2013-7488

perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.

CVSS3: 7.5
4%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2013-7484

Zabbix before 5.0 represents passwords in the users table with unsalted MD5.

CVSS3: 7.5
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2013-7470

cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.

CVSS3: 5.9
3%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2013-7469

Seafile through 6.2.11 always uses the same Initialization Vector (IV) with Cipher Block Chaining (CBC) Mode to encrypt private data, making it easier to conduct chosen-plaintext attacks or dictionary attacks.

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2013-7464

In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.

CVSS3: 8.8
1%
Низкий
около 8 лет назад
ubuntu логотип
CVE-2013-7459

Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.

CVSS3: 9.8
10%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2013-7458

linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.

CVSS3: 3.3
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2013-7457

Unspecified vulnerability in the Qualcomm components in Android before 2016-07-05 allows attackers to gain privileges via a crafted application.

CVSS3: 7.8
0%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2013-7456

gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted image that is mishandled by the imagescale function.

CVSS3: 7.6
4%
Низкий
около 10 лет назад
ubuntu логотип
CVE-2013-7455

Double free vulnerability in the DefaultICCintents function in cmscnvrt.c in liblcms2 in Little CMS 2.x before 2.6 allows remote attackers to execute arbitrary code via a malformed ICC profile that triggers an error in the default intent handler.

CVSS3: 9.8
6%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2013-7454

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden strings.

CVSS3: 6.1
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2013-7453

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via vectors related to UI redressing.

CVSS3: 6.1
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2013-7452

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via a crafted javascript URI.

CVSS3: 6.1
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2013-7451

The validator module before 1.1.0 for Node.js allows remote attackers to bypass the XSS filter via a nested tag.

CVSS3: 6.1
2%
Низкий
больше 9 лет назад
ubuntu логотип
CVE-2013-7449

The ssl_do_connect function in common/server.c in HexChat before 2.10.2, XChat, and XChat-GNOME does not verify that the server hostname matches a domain name in the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.

CVSS3: 6.5
1%
Низкий
больше 10 лет назад

Уязвимостей на страницу