Количество 26 124
Количество 26 124
CVE-2023-32233
In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled.
CVE-2023-32216
Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113.
CVE-2023-32212
An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
CVE-2023-32210
Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. In certain circumstances it might have been possible to cause a document to be loaded with a higher privileged principal than intended. This vulnerability affects Firefox < 113.
CVE-2023-3220
An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c lacks check of the return value of kzalloc() and will cause the NULL Pointer Dereference.
CVE-2023-32208
Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113.
CVE-2023-3217
Chromium: CVE-2023-3217 Use after free in WebXR
CVE-2023-3216
Chromium: CVE-2023-3216 Type Confusion in V8
CVE-2023-3215
Chromium: CVE-2023-3215 Use after free in WebRTC
CVE-2023-3214
Chromium: CVE-2023-3214 Use after free in Autofill payments
CVE-2023-3212
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.
CVE-2023-32085
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
CVE-2023-32084
HTTP.sys Denial of Service Vulnerability
CVE-2023-32083
Microsoft Failover Cluster Information Disclosure Vulnerability
CVE-2023-32082
etcd key name can be accessed via LeaseTimeToLive API
CVE-2023-32067
CVE-2023-32057
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
CVE-2023-32056
Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability
CVE-2023-32055
Active Template Library Elevation of Privilege Vulnerability
CVE-2023-32054
Volume Shadow Copy Elevation of Privilege Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-32233 In the Linux kernel through 6.3.1 a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged local users can obtain root privileges. This occurs because anonymous sets are mishandled. | CVSS3: 7.8 | 13% Средний | больше 3 лет назад | |
CVE-2023-32216 Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113. | 1% Низкий | 6 месяцев назад | ||
CVE-2023-32212 An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. | 1% Низкий | 6 месяцев назад | ||
CVE-2023-32210 Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. In certain circumstances it might have been possible to cause a document to be loaded with a higher privileged principal than intended. This vulnerability affects Firefox < 113. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-3220 An issue was discovered in the Linux kernel through 6.1-rc8. dpu_crtc_atomic_check in drivers/gpu/drm/msm/disp/dpu1/dpu_crtc.c lacks check of the return value of kzalloc() and will cause the NULL Pointer Dereference. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-32208 Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113. | 1% Низкий | 6 месяцев назад | ||
CVE-2023-3217 Chromium: CVE-2023-3217 Use after free in WebXR | 13% Средний | около 3 лет назад | ||
CVE-2023-3216 Chromium: CVE-2023-3216 Type Confusion in V8 | 1% Низкий | около 3 лет назад | ||
CVE-2023-3215 Chromium: CVE-2023-3215 Use after free in WebRTC | 14% Средний | около 3 лет назад | ||
CVE-2023-3214 Chromium: CVE-2023-3214 Use after free in Autofill payments | 1% Низкий | около 3 лет назад | ||
CVE-2023-3212 A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic. | CVSS3: 4.4 | 0% Низкий | около 3 лет назад | |
CVE-2023-32085 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | около 3 лет назад | |
CVE-2023-32084 HTTP.sys Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | около 3 лет назад | |
CVE-2023-32083 Microsoft Failover Cluster Information Disclosure Vulnerability | CVSS3: 6.5 | 2% Низкий | около 3 лет назад | |
CVE-2023-32082 etcd key name can be accessed via LeaseTimeToLive API | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
CVSS3: 7.5 | 2% Низкий | около 3 лет назад | ||
CVE-2023-32057 Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability | CVSS3: 9.8 | 2% Низкий | около 3 лет назад | |
CVE-2023-32056 Windows Server Update Service (WSUS) Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-32055 Active Template Library Elevation of Privilege Vulnerability | CVSS3: 6.7 | 0% Низкий | около 3 лет назад | |
CVE-2023-32054 Volume Shadow Copy Elevation of Privilege Vulnerability | CVSS3: 7.3 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу