Количество 26 124
Количество 26 124
CVE-2023-5217
Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx
CVE-2023-52160
CVE-2023-5215
Libnbd: crash or misbehaviour when nbd server returns an unexpected block size
CVE-2023-52071
CVE-2023-5197
Use-after-free in Linux kernel's netfilter: nf_tables component
CVE-2023-5187
Chromium: CVE-2023-5187 Use after free in Extensions
CVE-2023-5186
Chromium: CVE-2023-5186 Use after free in Passwords
CVE-2023-5178
Kernel: use after free in nvmet_tcp_free_crypto in nvme
CVE-2023-51782
CVE-2023-51781
CVE-2023-51780
CVE-2023-51779
CVE-2023-5176
Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
CVE-2023-51764
Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address allowing bypass of an SPF protection mechanism. This occurs because Postfix supports <LF>.<CR><LF> but some other popular e-mail servers do not. To prevent attack variants (by always disallowing <LF> without <CR>) a different solution is required such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23 3.6.13 3.7.9 3.8.4 or 3.9.
CVE-2023-51714
An issue was discovered in the HTTP2 implementation in Qt before 5.15.17 6.x before 6.2.11 6.3.x through 6.5.x before 6.5.4 and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.
CVE-2023-51592
BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2023-51589
BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2023-51580
BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2023-5156
CVE-2023-51385
In ssh in OpenSSH before 9.6 OS command injection might occur if a user name or host name has shell metacharacters and this name is referenced by an expansion token in certain situations. For example an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-5217 Chromium: CVE-2023-5217 Heap buffer overflow in vp8 encoding in libvpx | 49% Средний | почти 3 года назад | ||
CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | ||
CVE-2023-5215 Libnbd: crash or misbehaviour when nbd server returns an unexpected block size | CVSS3: 6.5 | 1% Низкий | почти 3 года назад | |
| около 2 лет назад | ||||
CVE-2023-5197 Use-after-free in Linux kernel's netfilter: nf_tables component | CVSS3: 6.6 | 0% Низкий | почти 3 года назад | |
CVE-2023-5187 Chromium: CVE-2023-5187 Use after free in Extensions | 1% Низкий | почти 3 года назад | ||
CVE-2023-5186 Chromium: CVE-2023-5186 Use after free in Passwords | 1% Низкий | почти 3 года назад | ||
CVE-2023-5178 Kernel: use after free in nvmet_tcp_free_crypto in nvme | CVSS3: 8.8 | 9% Низкий | почти 3 года назад | |
CVSS3: 7 | 0% Низкий | больше 2 лет назад | ||
CVSS3: 7 | 0% Низкий | больше 2 лет назад | ||
CVSS3: 7 | 1% Низкий | больше 2 лет назад | ||
CVSS3: 7 | 0% Низкий | около 2 лет назад | ||
CVE-2023-5176 Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-51764 Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address allowing bypass of an SPF protection mechanism. This occurs because Postfix supports <LF>.<CR><LF> but some other popular e-mail servers do not. To prevent attack variants (by always disallowing <LF> without <CR>) a different solution is required such as the smtpd_forbid_bare_newline=yes option with a Postfix minimum version of 3.5.23 3.6.13 3.7.9 3.8.4 or 3.9. | CVSS3: 5.3 | 3% Низкий | больше 2 лет назад | |
CVE-2023-51714 An issue was discovered in the HTTP2 implementation in Qt before 5.15.17 6.x before 6.2.11 6.3.x through 6.5.x before 6.5.4 and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
CVE-2023-51592 BlueZ Audio Profile AVRCP parse_media_folder Out-Of-Bounds Read Information Disclosure Vulnerability | 1% Низкий | 12 месяцев назад | ||
CVE-2023-51589 BlueZ Audio Profile AVRCP parse_media_element Out-Of-Bounds Read Information Disclosure Vulnerability | 1% Низкий | 12 месяцев назад | ||
CVE-2023-51580 BlueZ Audio Profile AVRCP avrcp_parse_attribute_list Out-Of-Bounds Read Information Disclosure Vulnerability | 1% Низкий | 12 месяцев назад | ||
CVSS3: 7.5 | 1% Низкий | почти 3 года назад | ||
CVE-2023-51385 In ssh in OpenSSH before 9.6 OS command injection might occur if a user name or host name has shell metacharacters and this name is referenced by an expansion token in certain situations. For example an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name. | CVSS3: 6.5 | 20% Средний | 6 месяцев назад |
Уязвимостей на страницу