Количество 26 124
Количество 26 124
CVE-2023-6246
Glibc: heap-based buffer overflow in __vsyslog_internal()
CVE-2023-6237
CVE-2023-6228
Libtiff: heap-based buffer overflow in cpstriptotile() in tools/tiffcp.c
CVE-2023-6213
Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120.
CVE-2023-6212
Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6211
If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.
CVE-2023-6210
When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120.
CVE-2023-6209
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6208
When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6206
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6205
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6204
On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6200
Kernel: icmpv6 router advertisement packets aka linux tcp/ip remote code execution vulnerability
CVE-2023-6175
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark
CVE-2023-6174
Out-of-bounds Read in Wireshark
CVE-2023-6129
CVE-2023-6121
CVE-2023-6112
Chromium: CVE-2023-6112 Use after free in Navigation
CVE-2023-6111
Use-after-free in Linux kernel's netfilter: nf_tables component
CVE-2023-6040
An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-6246 Glibc: heap-based buffer overflow in __vsyslog_internal() | CVSS3: 7.8 | 5% Низкий | 6 месяцев назад | |
CVSS3: 5.9 | 2% Низкий | почти 2 года назад | ||
CVE-2023-6228 Libtiff: heap-based buffer overflow in cpstriptotile() in tools/tiffcp.c | CVSS3: 3.3 | 0% Низкий | больше 1 года назад | |
CVE-2023-6213 Memory safety bugs present in Firefox 119. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-6212 Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | 1% Низкий | 6 месяцев назад | ||
CVE-2023-6211 If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120. | 0% Низкий | 6 месяцев назад | ||
CVE-2023-6210 When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120. | 1% Низкий | 6 месяцев назад | ||
CVE-2023-6209 Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-6208 When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-6206 The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | 1% Низкий | 6 месяцев назад | ||
CVE-2023-6205 It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-6204 On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-6200 Kernel: icmpv6 router advertisement packets aka linux tcp/ip remote code execution vulnerability | CVSS3: 7.5 | 2% Низкий | 6 месяцев назад | |
CVE-2023-6175 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Wireshark | CVSS3: 7.8 | 3% Низкий | около 1 года назад | |
CVE-2023-6174 Out-of-bounds Read in Wireshark | CVSS3: 6.5 | 1% Низкий | около 1 года назад | |
CVSS3: 6.5 | 2% Низкий | больше 2 лет назад | ||
CVSS3: 4.3 | 2% Низкий | больше 1 года назад | ||
CVE-2023-6112 Chromium: CVE-2023-6112 Use after free in Navigation | 30% Средний | почти 3 года назад | ||
CVE-2023-6111 Use-after-free in Linux kernel's netfilter: nf_tables component | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
CVE-2023-6040 An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family) | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу