Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 77 240

Количество 77 240

ubuntu логотип

CVE-2013-2228

почти 7 лет назад

SaltStack RSA Key Generation allows remote users to decrypt communications

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2013-2227

почти 7 лет назад

GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

CVSS3: 7.5
EPSS: Средний
ubuntu логотип

CVE-2013-2226

больше 12 лет назад

Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to ajax/comments.php.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-2225

больше 12 лет назад

inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to front/ticket.form.php.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2013-2224

около 13 лет назад

A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.

CVSS2: 6.9
EPSS: Низкий
ubuntu логотип

CVE-2013-2223

почти 13 лет назад

GNU ZRTPCPP before 3.2.0 allows remote attackers to obtain sensitive information (uninitialized heap memory) or cause a denial of service (out-of-bounds read) via a crafted packet, as demonstrated by a truncated Ping packet that is not properly handled by the getEpHash function.

CVSS2: 5.8
EPSS: Низкий
ubuntu логотип

CVE-2013-2222

почти 13 лет назад

Multiple stack-based buffer overflows in GNU ZRTPCPP before 3.2.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ZRTP Hello packet to the (1) ZRtp::findBestSASType, (2) ZRtp::findBestAuthLen, (3) ZRtp::findBestCipher, (4) ZRtp::findBestHash, or (5) ZRtp::findBestPubKey functions.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-2221

почти 13 лет назад

Heap-based buffer overflow in the ZRtp::storeMsgTemp function in GNU ZRTPCPP before 3.2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large packet.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-2220

около 13 лет назад

Buffer overflow in the radius_get_vendor_attr function in the Radius extension before 1.2.7 for PHP allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large Vendor Specific Attributes (VSA) length value.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-2219

около 13 лет назад

The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-2218

почти 13 лет назад

Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be skipped, as demonstrated by the "virsh iface-list --inactive" command.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2013-2217

почти 13 лет назад

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

CVSS2: 1.2
EPSS: Низкий
ubuntu логотип

CVE-2013-2214

больше 12 лет назад

status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.

CVSS2: 4
EPSS: Низкий
ubuntu логотип

CVE-2013-2213

больше 6 лет назад

The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.

CVSS3: 5.5
EPSS: Низкий
ubuntu логотип

CVE-2013-2212

около 13 лет назад

The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GFN range.

CVSS2: 5.7
EPSS: Низкий
ubuntu логотип

CVE-2013-2211

около 13 лет назад

The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspecified vectors.

CVSS2: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2013-2210

около 13 лет назад

Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions. NOTE: this is due to an incorrect fix for CVE-2013-2154.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2013-2208

почти 13 лет назад

tpp 1.3.1 allows remote attackers to execute arbitrary commands via a --exec command in a TPP template file.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-2207

почти 13 лет назад

pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2013-2206

около 13 лет назад

The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.

CVSS2: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-2228

SaltStack RSA Key Generation allows remote users to decrypt communications

CVSS3: 8.1
2%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2013-2227

GLPI 0.83.7 has Local File Inclusion in common.tabs.php.

CVSS3: 7.5
13%
Средний
почти 7 лет назад
ubuntu логотип
CVE-2013-2226

Multiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1) users_id_assign parameter to ajax/ticketassigninformation.php, (2) filename parameter to front/document.form.php, or (3) table parameter to ajax/comments.php.

CVSS2: 7.5
3%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2225

inc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields parameter to front/ticket.form.php.

CVSS2: 6.4
8%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2224

A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.

CVSS2: 6.9
0%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2013-2223

GNU ZRTPCPP before 3.2.0 allows remote attackers to obtain sensitive information (uninitialized heap memory) or cause a denial of service (out-of-bounds read) via a crafted packet, as demonstrated by a truncated Ping packet that is not properly handled by the getEpHash function.

CVSS2: 5.8
3%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-2222

Multiple stack-based buffer overflows in GNU ZRTPCPP before 3.2.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted ZRTP Hello packet to the (1) ZRtp::findBestSASType, (2) ZRtp::findBestAuthLen, (3) ZRtp::findBestCipher, (4) ZRtp::findBestHash, or (5) ZRtp::findBestPubKey functions.

CVSS2: 6.8
5%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-2221

Heap-based buffer overflow in the ZRtp::storeMsgTemp function in GNU ZRTPCPP before 3.2.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large packet.

CVSS2: 7.5
4%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-2220

Buffer overflow in the radius_get_vendor_attr function in the Radius extension before 1.2.7 for PHP allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large Vendor Specific Attributes (VSA) length value.

CVSS2: 7.5
4%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2013-2219

The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for the attribute.

CVSS2: 4
2%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2013-2218

Double free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote attackers to cause a denial of service (libvirtd crash) via a filtering flag that causes an interface to be skipped, as demonstrated by the "virsh iface-list --inactive" command.

CVSS2: 5
8%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-2217

cache.py in Suds 0.4, when tempdir is set to None, allows local users to redirect SOAP queries and possibly have other unspecified impact via a symlink attack on a cache file with a predictable name in /tmp/suds/.

CVSS2: 1.2
1%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-2214

status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.

CVSS2: 4
4%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-2213

The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms by predicting the generator output.

CVSS3: 5.5
0%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2013-2212

The vmx_set_uc_mode function in Xen 3.3 through 4.3, when disabling caches, allows local HVM guests with access to memory mapped I/O regions to cause a denial of service (CPU consumption and possibly hypervisor or guest kernel panic) via a crafted GFN range.

CVSS2: 5.7
1%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2013-2211

The libxenlight (libxl) toolstack library in Xen 4.0.x, 4.1.x, and 4.2.x uses weak permissions for xenstore keys for paravirtualised and emulated serial console devices, which allows local guest administrators to modify the xenstore value via unspecified vectors.

CVSS2: 7.4
1%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2013-2210

Heap-based buffer overflow in the XML Signature Reference functionality in Apache Santuario XML Security for C++ (aka xml-security-c) before 1.7.2 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via malformed XPointer expressions. NOTE: this is due to an incorrect fix for CVE-2013-2154.

CVSS2: 7.5
6%
Низкий
около 13 лет назад
ubuntu логотип
CVE-2013-2208

tpp 1.3.1 allows remote attackers to execute arbitrary commands via a --exec command in a TPP template file.

CVSS2: 6.8
3%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-2207

pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.

CVSS2: 2.6
0%
Низкий
почти 13 лет назад
ubuntu логотип
CVE-2013-2206

The sctp_sf_do_5_2_4_dupcook function in net/sctp/sm_statefuns.c in the SCTP implementation in the Linux kernel before 3.8.5 does not properly handle associations during the processing of a duplicate COOKIE ECHO chunk, which allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted SCTP traffic.

CVSS2: 5.4
5%
Низкий
около 13 лет назад

Уязвимостей на страницу