Количество 26 124
Количество 26 124
CVE-2023-40549
Shim: out-of-bounds read in verify_buffer_authenticode() malformed pe file
CVE-2023-40548
Shim: interger overflow leads to heap buffer overflow in verify_sbat_section on 32-bits systems
CVE-2023-40547
Redhat: CVE-2023-40547 Shim - RCE in HTTP boot support may lead to secure boot bypass
CVE-2023-40546
Shim: out-of-bounds read printing error messages
CVE-2023-4051
Full screen notification obscured by file open dialog
CVE-2023-4039
CVE-2023-40359
xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e. neither alphanumeric nor underscore) aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain experimental feature.
CVE-2023-40305
GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file.
CVE-2023-40283
An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled.
CVE-2023-40225
HAProxy through 2.0.32 2.1.x and 2.2.x through 2.2.30 2.3.x and 2.4.x through 2.4.23 2.5.x and 2.6.x before 2.6.15 2.7.x before 2.7.10 and 2.8.x before 2.8.2 forwards empty Content-Length headers violating RFC 9110 section 8.6. In uncommon cases an HTTP/1 server behind HAProxy may interpret the payload as an extra request.
CVE-2023-40217
CVE-2023-4015
Use-after-free in Linux kernel's netfilter: nf_tables component
CVE-2023-4004
Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()
CVE-2023-40030
Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports
CVE-2023-4001
Grub2: bypass the grub password protection feature
CVE-2023-39976
log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered.
CVE-2023-39956
Electron: CVE-2023-39956 -Visual Studio Code Remote Code Execution Vulnerability
CVE-2023-39810
An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal.
CVE-2023-39804
CVE-2023-3978
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-40549 Shim: out-of-bounds read in verify_buffer_authenticode() malformed pe file | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2023-40548 Shim: interger overflow leads to heap buffer overflow in verify_sbat_section on 32-bits systems | CVSS3: 7.4 | 0% Низкий | больше 1 года назад | |
CVE-2023-40547 Redhat: CVE-2023-40547 Shim - RCE in HTTP boot support may lead to secure boot bypass | CVSS3: 8.3 | 5% Низкий | больше 1 года назад | |
CVE-2023-40546 Shim: out-of-bounds read printing error messages | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2023-4051 Full screen notification obscured by file open dialog | 1% Низкий | 6 месяцев назад | ||
CVSS3: 4.8 | 1% Низкий | почти 3 года назад | ||
CVE-2023-40359 xterm before 380 supports ReGIS reporting for character-set names even if they have unexpected characters (i.e. neither alphanumeric nor underscore) aka a pointer/overflow issue. This can only occur for xterm installations that are configured at compile time to use a certain experimental feature. | CVSS3: 9.8 | 1% Низкий | почти 3 года назад | |
CVE-2023-40305 GNU indent 2.2.13 has a heap-based buffer overflow in search_brace in indent.c via a crafted file. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2023-40283 An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is a use-after-free because the children of an sk are mishandled. | CVSS3: 7.8 | 1% Низкий | почти 3 года назад | |
CVE-2023-40225 HAProxy through 2.0.32 2.1.x and 2.2.x through 2.2.30 2.3.x and 2.4.x through 2.4.23 2.5.x and 2.6.x before 2.6.15 2.7.x before 2.7.10 and 2.8.x before 2.8.2 forwards empty Content-Length headers violating RFC 9110 section 8.6. In uncommon cases an HTTP/1 server behind HAProxy may interpret the payload as an extra request. | CVSS3: 7.2 | 2% Низкий | почти 3 года назад | |
CVSS3: 5.3 | 1% Низкий | почти 3 года назад | ||
CVE-2023-4015 Use-after-free in Linux kernel's netfilter: nf_tables component | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
CVE-2023-4004 Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove() | CVSS3: 7.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-40030 Malicious dependencies can inject arbitrary JavaScript into cargo-generated timing reports | CVSS3: 6.1 | 1% Низкий | 6 месяцев назад | |
CVE-2023-4001 Grub2: bypass the grub password protection feature | 1% Низкий | 6 месяцев назад | ||
CVE-2023-39976 log_blackbox.c in libqb before 2.0.8 allows a buffer overflow via long log messages because the header size is not considered. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
CVE-2023-39956 Electron: CVE-2023-39956 -Visual Studio Code Remote Code Execution Vulnerability | 1% Низкий | почти 3 года назад | ||
CVE-2023-39810 An issue in the CPIO command of Busybox v1.33.2 allows attackers to execute a directory traversal. | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVSS3: 6.2 | 0% Низкий | больше 1 года назад | ||
CVSS3: 6.1 | 1% Низкий | почти 2 года назад |
Уязвимостей на страницу