Lucene search

K
ubuntucveUbuntu.comUB:CVE-2013-1436
HistoryOct 06, 2014 - 12:00 a.m.

CVE-2013-1436

2014-10-0600:00:00
ubuntu.com
ubuntu.com
7

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.067

Percentile

93.9%

The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows
remote attackers to execute arbitrary commands via a web page title, which
activates the commands when the user clicks on the xmobar window title, as
demonstrated using an action tag.

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

EPSS

0.067

Percentile

93.9%