Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 337

Количество 77 337

ubuntu логотип

CVE-2013-6373

почти 13 лет назад

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

CVSS2: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2013-6372

больше 12 лет назад

The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2013-6371

больше 12 лет назад

The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2013-6370

больше 12 лет назад

Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2013-6369

больше 12 лет назад

Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted image file.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-6368

больше 12 лет назад

The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.

CVSS2: 6.2
EPSS: Низкий
ubuntu логотип

CVE-2013-6367

больше 12 лет назад

The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value.

CVSS2: 5.7
EPSS: Низкий
ubuntu логотип

CVE-2013-6365

почти 7 лет назад

Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2013-6364

почти 7 лет назад

Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2013-6359

больше 12 лет назад

Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-6357

почти 13 лет назад

Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-6348

почти 13 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-6340

почти 13 лет назад

epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly determine the amount of remaining data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-6339

почти 13 лет назад

The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the OpenWire dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (loop) via a crafted packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-6338

почти 13 лет назад

The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-6337

почти 13 лет назад

Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-6336

почти 13 лет назад

The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 uses an incorrect pointer chain, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2013-6283

почти 13 лет назад

VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a URL in a m3u file.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-6282

почти 13 лет назад

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

CVSS3: 8.8
EPSS: Средний
ubuntu логотип

CVE-2013-6275

почти 7 лет назад

Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-6373

The Exclusion plugin before 0.9 for Jenkins does not properly prevent access to resource locks, which allows remote authenticated users to list and release resources via unspecified vectors.

CVSS2: 5.5
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-6372

The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.

CVSS2: 2.1
0%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-6371

The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.

CVSS2: 5
3%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-6370

Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors.

CVSS2: 5
4%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-6369

Stack-based buffer overflow in the jbg_dec_in function in libjbig/jbig.c in JBIG-KIT before 2.1 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted image file.

CVSS2: 6.8
3%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-6368

The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.

CVSS2: 6.2
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-6367

The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value.

CVSS2: 5.7
1%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-6365

Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions

CVSS3: 5.3
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2013-6364

Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book

CVSS3: 8.8
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2013-6359

Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-6357

Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator.

CVSS2: 6.8
2%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-6348

Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (2) showConfig.action in config-browser/.

CVSS2: 4.3
6%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-6340

epan/dissectors/packet-tcp.c in the TCP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly determine the amount of remaining data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-6339

The dissect_openwire_type function in epan/dissectors/packet-openwire.c in the OpenWire dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (loop) via a crafted packet.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-6338

The dissect_sip_common function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 does not properly initialize a data structure, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-6337

Unspecified vulnerability in the NBAP dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-6336

The ieee802154_map_rec function in epan/dissectors/packet-ieee802154.c in the IEEE 802.15.4 dissector in Wireshark 1.8.x before 1.8.11 and 1.10.x before 1.10.3 uses an incorrect pointer chain, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-6283

VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in a URL in a m3u file.

CVSS2: 7.5
10%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-6282

The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not validate certain addresses, which allows attackers to read or modify the contents of arbitrary kernel memory locations via a crafted application, as exploited in the wild against Android devices in October and November 2013.

CVSS3: 8.8
40%
Средний
почти 13 лет назад
ubuntu логотип
CVE-2013-6275

Multiple CSRF issues in Horde Groupware Webmail Edition 5.1.2 and earlier in basic.php.

CVSS3: 6.5
2%
Низкий
почти 7 лет назад

Уязвимостей на страницу