Количество 26 124
Количество 26 124
CVE-2023-46838
Linux: netback processing of zero-length transmit fragment
CVE-2023-46813
An issue was discovered in the Linux kernel before 6.5.9 exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrary write access to kernel memory (and thus privilege escalation). This depends on a race condition through which userspace can replace an instruction before the #VC handler reads it.
CVE-2023-46753
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes e.g. one with only an unknown transit attribute.
CVE-2023-46752
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data leading to a crash.
CVE-2023-46673
It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API.
CVE-2023-4641
Shadow-utils: possible password leak during passwd(1) change
CVE-2023-46343
In the Linux kernel before 6.5.9 there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c.
CVE-2023-46316
In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3 the wrapper scripts do not properly parse command lines.
CVE-2023-46246
Integer Overflow in :history command in Vim
CVE-2023-4623
Use-after-free in Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) component
CVE-2023-46234
browserify-sign vulnerable via an upper bound check issue in `dsaVerify` that leads to a signature forgery attack
CVE-2023-4622
Use-after-free in Linux kernel's af_unix component
CVE-2023-46228
zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c lib/comp/zstd/zstd.c lib/dl/multipart.c or lib/header.c.
CVE-2023-46219
CVE-2023-46218
CVE-2023-46137
twisted.web has disordered HTTP pipeline response
CVE-2023-46136
Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning
CVE-2023-46129
xkeys Seal encryption used fixed key for all encryption
CVE-2023-4611
Use after free race between mbind() and vma-locked page fault
CVE-2023-46118
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-46838 Linux: netback processing of zero-length transmit fragment | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2023-46813 An issue was discovered in the Linux kernel before 6.5.9 exploitable by local users with userspace access to MMIO registers. Incorrect access checking in the #VC handler and instruction emulation of the SEV-ES emulation of MMIO accesses could lead to arbitrary write access to kernel memory (and thus privilege escalation). This depends on a race condition through which userspace can replace an instruction before the #VC handler reads it. | CVSS3: 7 | 1% Низкий | 6 месяцев назад | |
CVE-2023-46753 An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes e.g. one with only an unknown transit attribute. | CVSS3: 5.9 | 1% Низкий | почти 3 года назад | |
CVE-2023-46752 An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data leading to a crash. | CVSS3: 5.9 | 1% Низкий | 6 месяцев назад | |
CVE-2023-46673 It was identified that malformed scripts used in the script processor of an Ingest Pipeline could cause an Elasticsearch node to crash when calling the Simulate Pipeline API. | 1% Низкий | 11 дней назад | ||
CVE-2023-4641 Shadow-utils: possible password leak during passwd(1) change | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
CVE-2023-46343 In the Linux kernel before 6.5.9 there is a NULL pointer dereference in send_acknowledge in net/nfc/nci/spi.c. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
CVE-2023-46316 In buc Traceroute 2.0.12 through 2.1.2 before 2.1.3 the wrapper scripts do not properly parse command lines. | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
CVE-2023-46246 Integer Overflow in :history command in Vim | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
CVE-2023-4623 Use-after-free in Linux kernel's net/sched: sch_hfsc (HFSC qdisc traffic control) component | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
CVE-2023-46234 browserify-sign vulnerable via an upper bound check issue in `dsaVerify` that leads to a signature forgery attack | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
CVE-2023-4622 Use-after-free in Linux kernel's af_unix component | CVSS3: 7 | 1% Низкий | почти 3 года назад | |
CVE-2023-46228 zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c lib/comp/zstd/zstd.c lib/dl/multipart.c or lib/header.c. | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
CVSS3: 5.3 | 1% Низкий | больше 2 лет назад | ||
CVSS3: 6.5 | 2% Низкий | больше 2 лет назад | ||
CVE-2023-46137 twisted.web has disordered HTTP pipeline response | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
CVE-2023-46136 Werkzeug vulnerable to high resource usage when parsing multipart/form-data containing a large part with CR/LF character at the beginning | CVSS3: 8 | 1% Низкий | 6 месяцев назад | |
CVE-2023-46129 xkeys Seal encryption used fixed key for all encryption | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
CVE-2023-4611 Use after free race between mbind() and vma-locked page fault | CVSS3: 6.3 | 0% Низкий | почти 3 года назад | |
CVSS3: 4.9 | 1% Низкий | около 2 лет назад |
Уязвимостей на страницу