Количество 26 124
Количество 26 124
CVE-2023-35305
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-35304
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-35303
USB Audio Class System Driver Remote Code Execution Vulnerability
CVE-2023-35302
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVE-2023-35300
Remote Procedure Call Runtime Remote Code Execution Vulnerability
CVE-2023-35299
Windows Common Log File System Driver Elevation of Privilege Vulnerability
CVE-2023-35298
HTTP.sys Denial of Service Vulnerability
CVE-2023-35297
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
CVE-2023-35296
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-34969
D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus this is a denial-of-service vulnerability. The fixed versions are 1.12.28 1.14.8 and 1.15.6.
CVE-2023-3482
When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of 'about:blank'. This could have led to malicious websites storing tracking data without permission. This vulnerability affects Firefox < 115.
CVE-2023-3446
CVE-2023-34417
Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114.
CVE-2023-34411
The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9.
CVE-2023-34410
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
CVE-2023-3439
A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object potentially leading to a denial of service.
CVE-2023-34256
An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated "When modifying the block device while it is mounted by the filesystem" access.
CVE-2023-34241
CVE-2023-3422
Chromium: CVE-2023-3422 Use after free in Guest View
CVE-2023-3421
Chromium: CVE-2023-3421 Use after free in Media
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-35305 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
CVE-2023-35304 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
CVE-2023-35303 USB Audio Class System Driver Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-35302 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-35300 Remote Procedure Call Runtime Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-35299 Windows Common Log File System Driver Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
CVE-2023-35298 HTTP.sys Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | около 3 лет назад | |
CVE-2023-35297 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | CVSS3: 8.1 | 1% Низкий | около 3 лет назад | |
CVE-2023-35296 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | CVSS3: 6.5 | 2% Низкий | около 3 лет назад | |
CVE-2023-34969 D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic then an unprivileged user with the ability to connect to the same dbus-daemon can cause a dbus-daemon crash under some circumstances via an unreplyable message. When done on the well-known system bus this is a denial-of-service vulnerability. The fixed versions are 1.12.28 1.14.8 and 1.15.6. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-3482 When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of 'about:blank'. This could have led to malicious websites storing tracking data without permission. This vulnerability affects Firefox < 115. | 1% Низкий | 12 месяцев назад | ||
CVSS3: 5.3 | 7% Низкий | около 2 лет назад | ||
CVE-2023-34417 Memory safety bugs present in Firefox 113. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 114. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-34411 The xml-rs crate before 0.8.14 for Rust and Crab allows a denial of service (panic) via an invalid <! token (such as <!DOCTYPEs/%<!A nesting) in an XML document. The earliest affected version is 0.8.9. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2023-34410 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate. | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
CVE-2023-3439 A flaw was found in the MCTP protocol in the Linux kernel. The function mctp_unregister() reclaims the device's relevant resource when a netcard detaches. However a running routine may be unaware of this and cause the use-after-free of the mdev->addrs object potentially leading to a denial of service. | CVSS3: 4.7 | 0% Низкий | около 3 лет назад | |
CVE-2023-34256 An issue was discovered in the Linux kernel before 6.3.3. There is an out-of-bounds read in crc16 in lib/crc16.c when called from fs/ext4/super.c because ext4_group_desc_csum does not properly check an offset. NOTE: this is disputed by third parties because the kernel is not intended to defend against attackers with the stated "When modifying the block device while it is mounted by the filesystem" access. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVSS3: 7.1 | 1% Низкий | больше 2 лет назад | ||
CVE-2023-3422 Chromium: CVE-2023-3422 Use after free in Guest View | 1% Низкий | около 3 лет назад | ||
CVE-2023-3421 Chromium: CVE-2023-3421 Use after free in Media | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу