Количество 26 124
Количество 26 124
CVE-2023-3268
An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information.
CVE-2023-32681
Unintended leak of Proxy-Authorization header in requests
CVE-2023-32665
Gvariant deserialisation does not match spec for non-normal data
CVE-2023-32643
A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-32665.
CVE-2023-32636
A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499.
CVE-2023-32611
G_variant_byteswap() can take a long time with some non-normal inputs
CVE-2023-32573
In Qt before 5.15.14 6.0.x through 6.2.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1 QtSvg QSvgFont m_unitsPerEm initialization is mishandled.
CVE-2023-32570
VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.
CVE-2023-3255
CVE-2023-32559
A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x 18.x and 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventually take advantage of `process.binding('spawn_sync')` run arbitrary code outside of the limits defined in a `policy.json` file. Please note that at the time this CVE was issued the policy is an experimental feature of Node.js.
CVE-2023-3247
Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP
CVE-2023-32324
CVE-2023-32269
An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However in order for an attacker to exploit this the system must have netrom routing configured or the attacker must have the CAP_NET_ADMIN capability.
CVE-2023-32258
Session race condition remote code execution vulnerability
CVE-2023-32257
Session race condition remote code execution vulnerability
CVE-2023-32254
Tree connection race condition remote code execution vulnerability
CVE-2023-32252
Session null pointer dereference denial-of-service vulnerability
CVE-2023-32250
Session race condition remote code execution vulnerability
CVE-2023-32248
Tree connection null pointer dereference denial-of-service vulnerability
CVE-2023-32247
Session setup memory exhaustion denial-of-service vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-3268 An out of bounds (OOB) memory access flaw was found in the Linux kernel in relay_file_read_start_pos in kernel/relay.c in the relayfs. This flaw could allow a local attacker to crash the system or leak kernel internal information. | CVSS3: 7.1 | 0% Низкий | около 3 лет назад | |
CVE-2023-32681 Unintended leak of Proxy-Authorization header in requests | CVSS3: 6.1 | 3% Низкий | около 3 лет назад | |
CVE-2023-32665 Gvariant deserialisation does not match spec for non-normal data | CVSS3: 5.5 | 0% Низкий | 11 месяцев назад | |
CVE-2023-32643 A flaw was found in GLib. The GVariant deserialization code is vulnerable to a heap buffer overflow introduced by the fix for CVE-2023-32665. This bug does not affect any released version of GLib, but does affect GLib distributors who followed the guidance of GLib developers to backport the initial fix for CVE-2023-32665. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
CVE-2023-32636 A flaw was found in glib, where the gvariant deserialization code is vulnerable to a denial of service introduced by additional input validation added to resolve CVE-2023-29499. The offset table validation may be very slow. This bug does not affect any released version of glib but does affect glib distributors who followed the guidance of glib developers to backport the initial fix for CVE-2023-29499. | CVSS3: 4.7 | 1% Низкий | больше 1 года назад | |
CVE-2023-32611 G_variant_byteswap() can take a long time with some non-normal inputs | CVSS3: 5.5 | 0% Низкий | 11 месяцев назад | |
CVE-2023-32573 In Qt before 5.15.14 6.0.x through 6.2.x before 6.2.9 and 6.3.x through 6.5.x before 6.5.1 QtSvg QSvgFont m_unitsPerEm initialization is mishandled. | CVSS3: 6.5 | 1% Низкий | 6 месяцев назад | |
CVE-2023-32570 VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit. | 1% Низкий | 6 месяцев назад | ||
CVSS3: 6.5 | 2% Низкий | почти 2 года назад | ||
CVE-2023-32559 A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x 18.x and 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventually take advantage of `process.binding('spawn_sync')` run arbitrary code outside of the limits defined in a `policy.json` file. Please note that at the time this CVE was issued the policy is an experimental feature of Node.js. | CVSS3: 7.5 | 2% Низкий | почти 3 года назад | |
CVE-2023-3247 Missing error check and insufficient random bytes in HTTP Digest authentication for SOAP | CVSS3: 4.3 | 1% Низкий | около 3 лет назад | |
CVSS3: 5.5 | 1% Низкий | больше 2 лет назад | ||
CVE-2023-32269 An issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c there is a use-after-free because accept is also allowed for a successfully connected AF_NETROM socket. However in order for an attacker to exploit this the system must have netrom routing configured or the attacker must have the CAP_NET_ADMIN capability. | CVSS3: 6.7 | 0% Низкий | больше 3 лет назад | |
CVE-2023-32258 Session race condition remote code execution vulnerability | CVSS3: 8.1 | 3% Низкий | около 3 лет назад | |
CVE-2023-32257 Session race condition remote code execution vulnerability | CVSS3: 8.1 | 2% Низкий | около 3 лет назад | |
CVE-2023-32254 Tree connection race condition remote code execution vulnerability | CVSS3: 8.1 | 3% Низкий | около 3 лет назад | |
CVE-2023-32252 Session null pointer dereference denial-of-service vulnerability | CVSS3: 7.5 | 4% Низкий | около 3 лет назад | |
CVE-2023-32250 Session race condition remote code execution vulnerability | CVSS3: 8.1 | 3% Низкий | около 3 лет назад | |
CVE-2023-32248 Tree connection null pointer dereference denial-of-service vulnerability | CVSS3: 7.5 | 4% Низкий | около 3 лет назад | |
CVE-2023-32247 Session setup memory exhaustion denial-of-service vulnerability | CVSS3: 7.5 | 4% Низкий | около 3 лет назад |
Уязвимостей на страницу