Количество 26 124
Количество 26 124
CVE-2023-42465
Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value) and because the values do not resist flips of a single bit.
CVE-2023-4244
Use-after-free in Linux kernel's netfilter: nf_tables component
CVE-2023-42366
CVE-2023-42365
CVE-2023-42364
A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function.
CVE-2023-42363
CVE-2023-42282
CVE-2023-4208
Use-after-free in Linux kernel's net/sched: cls_u32 component
CVE-2023-4207
Use-after-free in Linux kernel's net/sched: cls_fw component
CVE-2023-4206
Use-after-free in Linux kernel's net/sched: cls_route component
CVE-2023-41953
GitHub: CVE-2022-41953 Git GUI Clone Remote Code Execution Vulnerability
CVE-2023-4194
Kernel: tap: tap_open(): correctly initialize socket uid next fix of i_uid to current_fsuid
CVE-2023-41915
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
CVE-2023-41913
strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message.
CVE-2023-41910
An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.
CVE-2023-41774
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-41773
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-41772
Win32k Elevation of Privilege Vulnerability
CVE-2023-41771
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
CVE-2023-41770
Layer 2 Tunneling Protocol Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-42465 Sudo before 1.9.15 might allow row hammer attacks (for authentication bypass or privilege escalation) because application logic sometimes is based on not equaling an error value (instead of equaling a success value) and because the values do not resist flips of a single bit. | CVSS3: 7 | 1% Низкий | больше 2 лет назад | |
CVE-2023-4244 Use-after-free in Linux kernel's netfilter: nf_tables component | CVSS3: 7 | 0% Низкий | почти 3 года назад | |
CVSS3: 5.5 | 0% Низкий | больше 1 года назад | ||
CVSS3: 5.5 | 0% Низкий | почти 2 года назад | ||
CVE-2023-42364 A use-after-free vulnerability in BusyBox v.1.36.1 allows attackers to cause a denial of service via a crafted awk pattern in the awk.c evaluate function. | CVSS3: 5.5 | 0% Низкий | 12 месяцев назад | |
CVSS3: 5.5 | 0% Низкий | почти 2 года назад | ||
CVSS3: 9.8 | 2% Низкий | больше 2 лет назад | ||
CVE-2023-4208 Use-after-free in Linux kernel's net/sched: cls_u32 component | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
CVE-2023-4207 Use-after-free in Linux kernel's net/sched: cls_fw component | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
CVE-2023-4206 Use-after-free in Linux kernel's net/sched: cls_route component | CVSS3: 7.8 | 1% Низкий | почти 3 года назад | |
CVE-2023-41953 GitHub: CVE-2022-41953 Git GUI Clone Remote Code Execution Vulnerability | 0% Низкий | больше 3 лет назад | ||
CVE-2023-4194 Kernel: tap: tap_open(): correctly initialize socket uid next fix of i_uid to current_fsuid | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-41915 OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0. | CVSS3: 8.1 | 1% Низкий | 6 месяцев назад | |
CVE-2023-41913 strongSwan before 5.9.12 has a buffer overflow and possible unauthenticated remote code execution via a DH public value that exceeds the internal buffer in charon-tkm's DH proxy. The earliest affected version is 5.3.0. An attack can occur via a crafted IKE_SA_INIT message. | CVSS3: 9.8 | 2% Низкий | 6 месяцев назад | |
CVE-2023-41910 An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c. | CVSS3: 9.8 | 1% Низкий | почти 3 года назад | |
CVE-2023-41774 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | CVSS3: 8.1 | 1% Низкий | почти 3 года назад | |
CVE-2023-41773 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | CVSS3: 8.1 | 1% Низкий | почти 3 года назад | |
CVE-2023-41772 Win32k Elevation of Privilege Vulnerability | CVSS3: 7.8 | 12% Средний | почти 3 года назад | |
CVE-2023-41771 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | CVSS3: 8.1 | 1% Низкий | почти 3 года назад | |
CVE-2023-41770 Layer 2 Tunneling Protocol Remote Code Execution Vulnerability | CVSS3: 8.1 | 1% Низкий | почти 3 года назад |
Уязвимостей на страницу