|
289531
|
- |
|
mit debian opensuse
|
kerberos_5 debian_linux opensuse
|
The setup_server_realm function in main.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.7, when multiple realms are configured, allows remote attackers to cause a deni…
|
CWE-476
NULL Pointer Dereference
|
CVE-2013-1418
|
2024-11-21 10:49 |
2013-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289532
|
- |
|
microsoft
|
office
|
Heap-based buffer overflow in Microsoft Office 2003 SP3 and 2007 SP3 allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) file, aka "Word Heap Overwrite Vulnera…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-1325
|
2024-11-21 10:49 |
2013-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289533
|
- |
|
microsoft
|
office_2013_rt office
|
Stack-based buffer overflow in Microsoft Office 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT allows remote attackers to execute arbitrary code via a crafted WordPerfect document (.wpd) fil…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-1324
|
2024-11-21 10:49 |
2013-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289534
|
- |
|
dlitz
|
pycrypto
|
The Crypto.Random.atfork function in PyCrypto before 2.6.1 does not properly reseed the pseudo-random number generator (PRNG) before allowing a child process to access it, which makes it easier for c…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1445
|
2024-11-21 10:49 |
2013-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289535
|
- |
|
debian marc_vertes
|
txt2man
|
A certain Debian patch for txt2man 1.5.5, as used in txt2man 1.5.5-2, 1.5.5-4, and others, allows local users to overwrite arbitrary files via a symlink attack on /tmp/2222.
|
CWE-59
Link Following
|
CVE-2013-1444
|
2024-11-21 10:49 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289536
|
- |
|
xen
|
xen
|
Xen 4.0 through 4.3.x, when using AVX or LWP capable CPUs, does not properly clear previous data from registers when using an XSAVE or XRSTOR to extend the state components of a saved or restored vCP…
|
CWE-200
Information Exposure
|
CVE-2013-1442
|
2024-11-21 10:49 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289537
|
- |
|
djangoproject
|
django
|
The authentication framework (django.contrib.auth) in Django 1.4.x before 1.4.8, 1.5.x before 1.5.4, and 1.6.x before 1.6 beta 4 allows remote attackers to cause a denial of service (CPU consumption)…
|
CWE-287
Improper Authentication
|
CVE-2013-1443
|
2024-11-21 10:49 |
2013-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289538
|
- |
|
simon_mcvittie
|
telepathy_gabble
|
The Wocky module in Telepathy Gabble before 0.16.6 and 0.17.x before 0.17.4, when connecting to a "legacy Jabber server," does not properly enforce the WockyConnector:tls-required flag, which allows …
|
CWE-20
Improper Input Validation
|
CVE-2013-1431
|
2024-11-21 10:49 |
2013-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289539
|
- |
|
exactcode
|
exactimage
|
econvert in ExactImage 0.8.9 and earlier does not properly initialize the setjmp variable, which allows context-dependent users to cause a denial of service (crash) via a crafted image file.
|
CWE-20
Improper Input Validation
|
CVE-2013-1441
|
2024-11-21 10:49 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289540
|
- |
|
libraw
|
libraw
|
The "faster LJPEG decoder" in libraw 0.13.x, 0.14.x, and 0.15.x before 0.15.4 allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a crafted photo file.
|
NVD-CWE-Other
|
CVE-2013-1439
|
2024-11-21 10:49 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|