Количество 26 124
Количество 26 124
CVE-2023-29543
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
CVE-2023-2953
CVE-2023-29538
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
CVE-2023-29537
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
CVE-2023-29499
Gvariant offset table entry size is not checked in is_normal()
CVE-2023-29491
CVE-2023-29469
CVE-2023-2941
Chromium: CVE-2023-2941 Inappropriate implementation in Extensions API
CVE-2023-2940
Chromium: CVE-2023-2940 Inappropriate implementation in Downloads
CVE-2023-29409
Large RSA keys can cause high CPU usage in crypto/tls
CVE-2023-29406
Insufficient sanitization of Host header in net/http
CVE-2023-29405
Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
CVE-2023-29404
CVE-2023-29403
Unsafe behavior in setuid/setgid binaries in runtime
CVE-2023-29402
CVE-2023-29400
Improper handling of empty HTML attributes in html/template
CVE-2023-2939
Chromium: CVE-2023-2939 Insufficient data validation in Installer
CVE-2023-2938
Chromium: CVE-2023-2938 Inappropriate implementation in Picture In Picture
CVE-2023-29383
In Shadow 4.13 it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g. adding a new user fails because \n is in the block list) it is possible to misrepresent the /etc/passwd file when viewed. Use of \r manipulations and Unicode characters to work around blocking of the : character make it possible to give the impression that a new user has been added. In other words an adversary may be able to convince a system administrator to take the system offline (an indirect social-engineered denial of service) by demonstrating that "cat /etc/passwd" shows a rogue user account.
CVE-2023-2937
Chromium: CVE-2023-2937 Inappropriate implementation in Picture In Picture
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-29543 An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | 1% Низкий | 12 месяцев назад | ||
CVSS3: 7.5 | 2% Низкий | почти 2 года назад | ||
CVE-2023-29538 Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | 0% Низкий | 12 месяцев назад | ||
CVE-2023-29537 Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-29499 Gvariant offset table entry size is not checked in is_normal() | CVSS3: 5.5 | 1% Низкий | больше 1 года назад | |
CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | ||
CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | ||
CVE-2023-2941 Chromium: CVE-2023-2941 Inappropriate implementation in Extensions API | 1% Низкий | около 3 лет назад | ||
CVE-2023-2940 Chromium: CVE-2023-2940 Inappropriate implementation in Downloads | 1% Низкий | около 3 лет назад | ||
CVE-2023-29409 Large RSA keys can cause high CPU usage in crypto/tls | CVSS3: 5.3 | 2% Низкий | 12 месяцев назад | |
CVE-2023-29406 Insufficient sanitization of Host header in net/http | CVSS3: 6.5 | 1% Низкий | 6 месяцев назад | |
CVE-2023-29405 Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go | CVSS3: 9.8 | 2% Низкий | 6 месяцев назад | |
CVSS3: 9.8 | 2% Низкий | около 3 лет назад | ||
CVE-2023-29403 Unsafe behavior in setuid/setgid binaries in runtime | CVSS3: 7.8 | 0% Низкий | 12 месяцев назад | |
CVSS3: 9.8 | 2% Низкий | почти 2 года назад | ||
CVE-2023-29400 Improper handling of empty HTML attributes in html/template | CVSS3: 7.3 | 1% Низкий | 12 месяцев назад | |
CVE-2023-2939 Chromium: CVE-2023-2939 Insufficient data validation in Installer | 0% Низкий | около 3 лет назад | ||
CVE-2023-2938 Chromium: CVE-2023-2938 Inappropriate implementation in Picture In Picture | 1% Низкий | около 3 лет назад | ||
CVE-2023-29383 In Shadow 4.13 it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is not possible to exploit this directly (e.g. adding a new user fails because \n is in the block list) it is possible to misrepresent the /etc/passwd file when viewed. Use of \r manipulations and Unicode characters to work around blocking of the : character make it possible to give the impression that a new user has been added. In other words an adversary may be able to convince a system administrator to take the system offline (an indirect social-engineered denial of service) by demonstrating that "cat /etc/passwd" shows a rogue user account. | CVSS3: 3.3 | 0% Низкий | больше 3 лет назад | |
CVE-2023-2937 Chromium: CVE-2023-2937 Inappropriate implementation in Picture In Picture | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу