Количество 26 124
Количество 26 124
CVE-2023-51384
In ssh-agent in OpenSSH before 9.6 certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys these constraints are only applied to the first key even if a PKCS#11 token returns multiple keys.
CVE-2023-51258
A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512.
CVE-2023-51257
CVE-2023-5115
Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files
CVE-2023-51043
In the Linux kernel before 6.4.5 drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload.
CVE-2023-51042
In the Linux kernel before 6.4.12 amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-free.
CVE-2023-50967
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
CVE-2023-50966
CVE-2023-5090
Kernel: kvm: svm: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs
CVE-2023-5088
Qemu: improper ide controller reset can lead to mbr overwrite
CVE-2023-50868
MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU
CVE-2023-50782
Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659
CVE-2023-50711
`serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access
CVE-2023-50658
The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
CVE-2023-50495
CVE-2023-50472
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c.
CVE-2023-50471
cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c.
CVE-2023-50431
sec_attest_info in drivers/accel/habanalabs/common/habanalabs_ioctl.c in the Linux kernel through 6.6.5 allows an information leak to user space because info->pad0 is not initialized.
CVE-2023-50387
MITRE: CVE-2023-50387 DNSSEC verification complexity can be exploited to exhaust CPU resources and stall DNS resolvers
CVE-2023-50230
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-51384 In ssh-agent in OpenSSH before 9.6 certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys these constraints are only applied to the first key even if a PKCS#11 token returns multiple keys. | CVSS3: 5.5 | 0% Низкий | 6 месяцев назад | |
CVE-2023-51258 A memory leak issue discovered in YASM v.1.3.0 allows a local attacker to cause a denial of service via the new_Token function in the modules/preprocs/nasm/nasm-pp:1512. | CVSS3: 5.5 | 0% Низкий | 6 месяцев назад | |
CVSS3: 7.8 | 0% Низкий | около 2 лет назад | ||
CVE-2023-5115 Ansible: malicious role archive can cause ansible-galaxy to overwrite arbitrary files | CVSS3: 6.3 | 1% Низкий | около 1 года назад | |
CVE-2023-51043 In the Linux kernel before 6.4.5 drivers/gpu/drm/drm_atomic.c has a use-after-free during a race condition between a nonblocking atomic commit and a driver unload. | CVSS3: 7 | 0% Низкий | больше 2 лет назад | |
CVE-2023-51042 In the Linux kernel before 6.4.12 amdgpu_cs_wait_all_fences in drivers/gpu/drm/amd/amdgpu/amdgpu_cs.c has a fence use-after-free. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
CVE-2023-50967 latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVSS3: 5.3 | 1% Низкий | почти 2 года назад | ||
CVE-2023-5090 Kernel: kvm: svm: improper check in svm_set_x2apic_msr_interception allows direct access to host x2apic msrs | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
CVE-2023-5088 Qemu: improper ide controller reset can lead to mbr overwrite | CVSS3: 6.4 | 0% Низкий | 6 месяцев назад | |
CVE-2023-50868 MITRE: CVE-2023-50868 NSEC3 closest encloser proof can exhaust CPU | CVSS3: 7.5 | 82% Высокий | около 2 лет назад | |
CVE-2023-50782 Python-cryptography: bleichenbacher timing oracle attack against rsa decryption - incomplete fix for cve-2020-25659 | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2023-50711 `serde` deserialization for `FamStructWrapper` lacks bound checks that could potentially lead to out-of-bounds memory access | CVSS3: 5.7 | 1% Низкий | больше 2 лет назад | |
CVE-2023-50658 The jose2go component before 1.6.0 for Go allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
CVSS3: 6.5 | 1% Низкий | больше 1 года назад | ||
CVE-2023-50472 cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_SetValuestring at cJSON.c. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
CVE-2023-50471 cJSON v1.7.16 was discovered to contain a segmentation violation via the function cJSON_InsertItemInArray at cJSON.c. | CVSS3: 7.5 | 2% Низкий | больше 2 лет назад | |
CVE-2023-50431 sec_attest_info in drivers/accel/habanalabs/common/habanalabs_ioctl.c in the Linux kernel through 6.6.5 allows an information leak to user space because info->pad0 is not initialized. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-50387 MITRE: CVE-2023-50387 DNSSEC verification complexity can be exploited to exhaust CPU resources and stall DNS resolvers | 100% Критический | больше 2 лет назад | ||
CVE-2023-50230 BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability | CVSS3: 7.1 | 1% Низкий | 11 месяцев назад |
Уязвимостей на страницу