LiveActive security incident?Get immediate response
CVE archive

February 2013

Browse CVE records published in February 2013, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 570 matching CVEs · Page 7 of 12.

Unknown · CVSS Not scored

CVE-2013-1772: The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a...

The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.

Published Feb 28, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1619: The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not prope...

The TLS implementation in GnuTLS before 2.12.23, 3.0.x before 3.0.28, and 3.1.x before 3.1.7 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Published Feb 8, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1634: A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network...

A denial of service vulnerability exists in some motherboard implementations of Intel e1000e/82574L network controller devices through 2013-02-06 where the device can be brought into a non-processing state when parsing 32 hex, 33 hex, or 34 hex byte values at the 0x47f offset. NOTE: A followup statement from Intel suggests that the root cause of this issue was an incorrectly configured EEPROM image.

Published Feb 13, 2020 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1618: The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MA...

The TLS implementation in Opera before 12.13 does not properly consider timing side-channel attacks on a MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Published Feb 8, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1574: The dissect_bthci_eir_ad_data function in epan/dissectors/packet-bthci_cmd.c in the Bluetooth HCI dissector...

The dissect_bthci_eir_ad_data function in epan/dissectors/packet-bthci_cmd.c in the Bluetooth HCI dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 uses an incorrect data type for a counter variable, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

Published Feb 3, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1580: The dissect_cmstatus_tlv function in plugins/docsis/packet-cmstatus.c in the DOCSIS CM-STATUS dissector in...

The dissect_cmstatus_tlv function in plugins/docsis/packet-cmstatus.c in the DOCSIS CM-STATUS dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 uses an incorrect data type for a position variable, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

Published Feb 3, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1624: The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not pro...

The TLS implementation in the Bouncy Castle Java library before 1.48 and C# library before 1.8 does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Published Feb 8, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1620: The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-ch...

The TLS implementation in Mozilla Network Security Services (NSS) does not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Published Feb 8, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1579: The rtps_util_add_bitmap function in epan/dissectors/packet-rtps.c in the RTPS dissector in Wireshark 1.6.x...

The rtps_util_add_bitmap function in epan/dissectors/packet-rtps.c in the RTPS dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly implement certain nested loops for processing bitmap data, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

Published Feb 3, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1577: The dissect_sip_p_charging_func_addresses function in epan/dissectors/packet-sip.c in the SIP dissector in...

The dissect_sip_p_charging_func_addresses function in epan/dissectors/packet-sip.c in the SIP dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle offset data associated with a quoted string, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

Published Feb 3, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1623: The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not properly consider timing side-channe...

The TLS and DTLS implementations in wolfSSL CyaSSL before 2.5.0 do not properly consider timing side-channel attacks on a noncompliant MAC check operation during the processing of malformed CBC padding, which allows remote attackers to conduct distinguishing attacks and plaintext-recovery attacks via statistical analysis of timing data for crafted packets, a related issue to CVE-2013-0169.

Published Feb 8, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1572: The dissect_oampdu_event_notification function in epan/dissectors/packet-slowprotocols.c in the IEEE 802.3...

The dissect_oampdu_event_notification function in epan/dissectors/packet-slowprotocols.c in the IEEE 802.3 Slow Protocols dissector in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle certain short lengths, which allows remote attackers to cause a denial of service (infinite loop) via a malformed packet.

Published Feb 3, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1578: The dissect_pw_eth_heuristic function in epan/dissectors/packet-pw-eth.c in Wireshark 1.6.x before 1.6.13 a...

The dissect_pw_eth_heuristic function in epan/dissectors/packet-pw-eth.c in Wireshark 1.6.x before 1.6.13 and 1.8.x before 1.8.5 does not properly handle apparent Ethernet address values at the beginning of MPLS data, which allows remote attackers to cause a denial of service (loop) via a malformed packet.

Published Feb 3, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1463: Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module...

Cross-site scripting (XSS) vulnerability in js/tabletools/zeroclipboard.swf in the WP-Table Reloaded module before 1.9.4 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be the same vulnerability as CVE-2013-1808. If so, it is likely that CVE-2013-1463 will be REJECTed.

Published Feb 7, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1455: Joomla!

Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to an "Undefined variable."

Published Feb 13, 2013 · Updated Aug 6, 2024

Unknown · CVSS Not scored

CVE-2013-1454: Joomla!

Joomla! 3.0.x through 3.0.2 allows attackers to obtain sensitive information via unspecified vectors related to "Coding errors."

Published Feb 13, 2013 · Updated Aug 6, 2024