Количество 26 124
Количество 26 124
CVE-2023-3420
Chromium: CVE-2023-3420 Type Confusion in V8
CVE-2023-34059
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
CVE-2023-34058
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
CVE-2023-33976
CVE-2023-33953
Denial-of-Service in gRPC
CVE-2023-33952
Kernel: vmwgfx: double free within the handling of vmw_buffer_object objects
CVE-2023-33951
Kernel: vmwgfx: race condition leading to information disclosure vulnerability
CVE-2023-3390
Use-after-free in Linux kernel's netfilter subsystem
CVE-2023-3389
Use after free in io_uring in the Linux Kernel
CVE-2023-3359
An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference.
CVE-2023-3358
A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system.
CVE-2023-3357
A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the system.
CVE-2023-3355
Null pointer dereference in submit_lookup_cmds() in drivers/gpu/drm/msm/msm_gem_submit.c
CVE-2023-3354
CVE-2023-33461
iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for function iniparser_getstring's return.
CVE-2023-33460
There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.
CVE-2023-3341
A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly
CVE-2023-3338
Crash due to a null pointer dereference in the dn_nsp_send function
CVE-2023-33288
An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition.
CVE-2023-33285
An issue was discovered in Qt 5.x before 5.15.14 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-3420 Chromium: CVE-2023-3420 Type Confusion in V8 | 56% Средний | около 3 лет назад | ||
CVE-2023-34059 open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs. | CVSS3: 7 | 0% Низкий | почти 3 года назад | |
CVE-2023-34058 VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html . | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
CVSS3: 7.5 | 0% Низкий | почти 2 года назад | ||
CVE-2023-33953 Denial-of-Service in gRPC | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
CVE-2023-33952 Kernel: vmwgfx: double free within the handling of vmw_buffer_object objects | CVSS3: 6.7 | 0% Низкий | около 3 лет назад | |
CVE-2023-33951 Kernel: vmwgfx: race condition leading to information disclosure vulnerability | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
CVE-2023-3390 Use-after-free in Linux kernel's netfilter subsystem | CVSS3: 7.8 | 1% Низкий | 11 месяцев назад | |
CVE-2023-3389 Use after free in io_uring in the Linux Kernel | CVSS3: 7.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-3359 An issue was discovered in the Linux kernel brcm_nvram_parse in drivers/nvmem/brcm_nvram.c. Lacks for the check of the return value of kzalloc() can cause the NULL Pointer Dereference. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-3358 A null pointer dereference was found in the Linux kernel's Integrated Sensor Hub (ISH) driver. This issue could allow a local user to crash the system. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-3357 A NULL pointer dereference flaw was found in the Linux kernel AMD Sensor Fusion Hub driver. This flaw allows a local user to crash the system. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-3355 Null pointer dereference in submit_lookup_cmds() in drivers/gpu/drm/msm/msm_gem_submit.c | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVSS3: 7.5 | 2% Низкий | около 2 лет назад | ||
CVE-2023-33461 iniparser v4.1 is vulnerable to NULL Pointer Dereference in function iniparser_getlongint which misses check NULL for function iniparser_getstring's return. | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
CVE-2023-33460 There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-3341 A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly | CVSS3: 7.5 | 3% Низкий | около 2 лет назад | |
CVE-2023-3338 Crash due to a null pointer dereference in the dn_nsp_send function | CVSS3: 6.5 | 8% Низкий | 6 месяцев назад | |
CVE-2023-33288 An issue was discovered in the Linux kernel before 6.2.9. A use-after-free was found in bq24190_remove in drivers/power/supply/bq24190_charger.c. It could allow a local attacker to crash the system due to a race condition. | CVSS3: 4.7 | 0% Низкий | около 3 лет назад | |
CVE-2023-33285 An issue was discovered in Qt 5.x before 5.15.14 6.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server. | CVSS3: 5.3 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу