Количество 26 124
Количество 26 124
CVE-2023-38430
An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID leading to an out-of-bounds read.
CVE-2023-38429
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.
CVE-2023-38428
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer leading to an out-of-bounds read.
CVE-2023-38427
An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.
CVE-2023-38426
An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length.
CVE-2023-38409
An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2fb_map points at the old fb_info).
CVE-2023-38408
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
CVE-2023-38403
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
CVE-2023-38325
The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options.
CVE-2023-38254
Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability
CVE-2023-3824
Buffer overflow and overread in phar_dir_read()
CVE-2023-3823
Security issue with external entity loading in XML without enabling it
CVE-2023-38197
An issue was discovered in Qt before 5.15.15 6.x before 6.2.10 and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
CVE-2023-38188
Azure Apache Hadoop Spoofing Vulnerability
CVE-2023-38187
Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
CVE-2023-38186
Windows Mobile Device Management Elevation of Privilege Vulnerability
CVE-2023-38185
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-38184
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
CVE-2023-38182
Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-38181
Microsoft Exchange Server Spoofing Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-38430 An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID leading to an out-of-bounds read. | CVSS3: 9.1 | 1% Низкий | около 3 лет назад | |
CVE-2023-38429 An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-38428 An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer leading to an out-of-bounds read. | CVSS3: 9.1 | 3% Низкий | около 3 лет назад | |
CVE-2023-38427 An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-38426 An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length. | CVSS3: 9.1 | 3% Низкий | около 3 лет назад | |
CVE-2023-38409 An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an assignment occurs only for the first vc the fbcon_registered_fb and fbcon_display arrays can be desynchronized in fbcon_mode_deleted (the con2fb_map points at the old fb_info). | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-38408 The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009. | CVSS3: 9.8 | 80% Высокий | около 3 лет назад | |
CVE-2023-38403 iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field. | CVSS3: 7.5 | 2% Низкий | около 3 лет назад | |
CVE-2023-38325 The cryptography package before 41.0.2 for Python mishandles SSH certificates that have critical options. | 1% Низкий | 10 дней назад | ||
CVE-2023-38254 Microsoft Message Queuing (MSMQ) Denial of Service Vulnerability | CVSS3: 6.5 | 2% Низкий | около 3 лет назад | |
CVE-2023-3824 Buffer overflow and overread in phar_dir_read() | CVSS3: 9.4 | 21% Средний | 4 дня назад | |
CVE-2023-3823 Security issue with external entity loading in XML without enabling it | CVSS3: 8.6 | 2% Низкий | 4 дня назад | |
CVE-2023-38197 An issue was discovered in Qt before 5.15.15 6.x before 6.2.10 and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion. | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-38188 Azure Apache Hadoop Spoofing Vulnerability | CVSS3: 4.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-38187 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-38186 Windows Mobile Device Management Elevation of Privilege Vulnerability | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-38185 Microsoft Exchange Server Remote Code Execution Vulnerability | CVSS3: 8.8 | 3% Низкий | около 3 лет назад | |
CVE-2023-38184 Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-38182 Microsoft Exchange Server Remote Code Execution Vulnerability | CVSS3: 8 | 6% Низкий | около 3 лет назад | |
CVE-2023-38181 Microsoft Exchange Server Spoofing Vulnerability | CVSS3: 8.8 | 11% Средний | около 3 лет назад |
Уязвимостей на страницу