CVE-2013-1031
published 2013-09-16CVE-2013-1031: Power Management in Apple Mac OS X before 10.8.5 does not properly perform locking upon occurrences of a power assertion, which allows physically proximate…
PriorityP411low3.3CVSS 2.0
AVLACMAuNCPIPAN
EPSS
0.35%
28.0th percentile
Power Management in Apple Mac OS X before 10.8.5 does not properly perform locking upon occurrences of a power assertion, which allows physically proximate attackers to bypass intended access restrictions by visiting an unattended workstation on which a locking failure had prevented the startup of the screen saver.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | <= 10.8.4 | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1789 poppler: Multiple null pointer de-references in the Poppler splash backend
bugzilla·2013-03-01·CVSS 4.3
CVE-2013-1789 [MEDIUM] CVE-2013-1789 poppler: Multiple null pointer de-references in the Poppler splash backend
CVE-2013-1789 poppler: Multiple null pointer de-references in the Poppler splash backend
Two bugs that lead to a denial of service (crash) were reported in poppler (fixed in version 0.22.1):
- Fix crash in broken file 1031.pdf.asan.48.15 [1].
- Do not crash in broken documents like 1007.pdf.asan.48.4 [2].
[1] http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=a9b8ab4657dec65b8b86c225d12c533ad7e984e2
[2] http://cgit.freedesktop.org/poppler/poppler/commit/?h=poppler-0.22&id=a205e71a2dbe0c8d4f4905a76a3f79ec522eacec
Discussion:
Created poppler tracking bugs for this issue
Affects: fedora-all [bug 917113]
---
poppler-0.20.2-10.fc18 has been pushed to the Fedora 18 stable repository. If problems still persist, please make note of it in this bug report.
---
poppler-0.
Bugzilla
CVE-2013-0196 OpenShift Enterprise and Online vulnerable to CSRF attack with REST API
bugzilla·2013-01-18·CVSS 6.5
CVE-2013-0196 [MEDIUM] CVE-2013-0196 OpenShift Enterprise and Online vulnerable to CSRF attack with REST API
CVE-2013-0196 OpenShift Enterprise and Online vulnerable to CSRF attack with REST API
Jeremy Choi ([email protected]) of Red Hat reports:
Description of problem:
Since the web console is using 'Basic authentication' and the REST API has no
CSRF attack protection mechanism, the credential, the Authorization: header,
can be sent when requesting the REST API via web browser. As a result, while
users are authenticated malicious links or scripts provided by attackers can
cause unwanted action.
Discussion:
Acknowledgements:
This issue was discovered by Jeremy Choi of the Red Hat Hosted and Shared
Services team.
---
This issue was addressed in http://rhn.redhat.com/errata/RHEA-2013-1031.html
2013-09-16
Published