Количество 26 124
Количество 26 124
CVE-2023-50229
BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2023-49994
Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c.
CVE-2023-49993
Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow
CVE-2023-49992
Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c.
CVE-2023-49991
Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c.
CVE-2023-49990
Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c.
CVE-2023-49921
An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printed in logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by removing this excessive logging. This issue only affects users that use Watcher and have a Watch defined that uses the search input and additionally have set the search input’s logger to DEBUG or finer, for example using: org.elasticsearch.xpack.watcher.input.search, org.elasticsearch.xpack.watcher.input, org.elasticsearch.xpack.watcher, or wider, since the loggers are hierarchical.
CVE-2023-49582
CVE-2023-49569
Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients
CVE-2023-49568
Maliciously crafted Git server replies can cause DoS on go-git clients
CVE-2023-49558
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component.
CVE-2023-49557
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component.
CVE-2023-49556
Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component.
CVE-2023-49555
An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component.
CVE-2023-49554
Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component.
CVE-2023-49355
decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same as CVE-2023-50246. The CVE-2023-50246 71c2ab5 reference mentions -10E-1000010001, which is not in normalized scientific notation.
CVE-2023-49295
CVE-2023-49292
Possible private key restoration in go package github.com/ecies/go
CVE-2023-49284
Command substitution output can trigger shell expansion in fish shell
CVE-2023-4921
Use-after-free in Linux kernel's net/sched: sch_qfq component
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-50229 BlueZ Phone Book Access Profile Heap-based Buffer Overflow Remote Code Execution Vulnerability | CVSS3: 7.1 | 2% Низкий | 6 месяцев назад | |
CVE-2023-49994 Espeak-ng 1.52-dev was discovered to contain a Floating Point Exception via the function PeaksToHarmspect at wavegen.c. | CVSS3: 5.5 | 0% Низкий | 6 месяцев назад | |
CVE-2023-49993 Espeak-ng 1.52-dev was discovered to contain a Buffer Overflow | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад | |
CVE-2023-49992 Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Overflow via the function RemoveEnding at dictionary.c. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
CVE-2023-49991 Espeak-ng 1.52-dev was discovered to contain a Stack Buffer Underflow via the function CountVowelPosition at synthdata.c. | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад | |
CVE-2023-49990 Espeak-ng 1.52-dev was discovered to contain a buffer-overflow via the function SetUpPhonemeTable at synthdata.c. | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
CVE-2023-49921 An issue was discovered by Elastic whereby Watcher search input logged the search query results on DEBUG log level. This could lead to raw contents of documents stored in Elasticsearch to be printed in logs. Elastic has released 8.11.2 and 7.17.16 that resolves this issue by removing this excessive logging. This issue only affects users that use Watcher and have a Watch defined that uses the search input and additionally have set the search input’s logger to DEBUG or finer, for example using: org.elasticsearch.xpack.watcher.input.search, org.elasticsearch.xpack.watcher.input, org.elasticsearch.xpack.watcher, or wider, since the loggers are hierarchical. | 0% Низкий | 5 дней назад | ||
CVSS3: 5.5 | 0% Низкий | почти 2 года назад | ||
CVE-2023-49569 Maliciously crafted Git server replies can lead to path traversal and RCE on go-git clients | CVSS3: 9.8 | 2% Низкий | около 2 лет назад | |
CVE-2023-49568 Maliciously crafted Git server replies can cause DoS on go-git clients | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
CVE-2023-49558 An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_mmac_params function in the modules/preprocs/nasm/nasm-pp.c component. | 0% Низкий | 12 месяцев назад | ||
CVE-2023-49557 An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the yasm_section_bcs_first function in the libyasm/section.c component. | 0% Низкий | 12 месяцев назад | ||
CVE-2023-49556 Buffer Overflow vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expr_delete_term function in the libyasm/expr.c component. | 0% Низкий | 12 месяцев назад | ||
CVE-2023-49555 An issue in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the expand_smacro function in the modules/preprocs/nasm/nasm-pp.c component. | 0% Низкий | 12 месяцев назад | ||
CVE-2023-49554 Use After Free vulnerability in YASM 1.3.0.86.g9def allows a remote attacker to cause a denial of service via the do_directive function in the modules/preprocs/nasm/nasm-pp.c component. | 0% Низкий | 12 месяцев назад | ||
CVE-2023-49355 decToString in decNumber/decNumber.c in jq 88f01a7 has a one-byte out-of-bounds write via the " []-1.2e-1111111111" input. NOTE: this is not the same as CVE-2023-50246. The CVE-2023-50246 71c2ab5 reference mentions -10E-1000010001, which is not in normalized scientific notation. | CVSS3: 7.5 | 1% Низкий | 12 месяцев назад | |
CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | ||
CVE-2023-49292 Possible private key restoration in go package github.com/ecies/go | CVSS3: 4.9 | 0% Низкий | 6 месяцев назад | |
CVE-2023-49284 Command substitution output can trigger shell expansion in fish shell | CVSS3: 6.6 | 0% Низкий | больше 2 лет назад | |
CVE-2023-4921 Use-after-free in Linux kernel's net/sched: sch_qfq component | CVSS3: 7.8 | 0% Низкий | почти 3 года назад |
Уязвимостей на страницу