CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
64272 | CVE-2013-4325 | Candidate | The check_permission_v1 function in base/pkit.py in HP Linux Imaging and Printing (HPLIP) through 3.13.9 does not properly use D-Bus for communication with a polkit authority, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64528 | CVE-2013-4581 | Candidate | GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH. | Assigned (20130612) | None (candidate not yet proposed) | View | |
64784 | CVE-2013-4837 | Candidate | Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832. | Assigned (20130712) | None (candidate not yet proposed) | View | |
65040 | CVE-2013-5093 | Candidate | The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object. | Assigned (20130808) | None (candidate not yet proposed) | View | |
65296 | CVE-2013-5349 | Candidate | Integer underflow in Picasa3.exe in Google Picasa before 3.9.0 Build 137.69 allows remote attackers to execute arbitrary code via a crafted JPEG tag that triggers a heap-based buffer overflow, as demonstrated using a Canon RAW CR2 file with a large JPEG tag value and a small size. | Assigned (20130821) | None (candidate not yet proposed) | View |
Page 1346 of 20943, showing 5 records out of 104715 total, starting on record 6726, ending on 6730