Количество 26 124
Количество 26 124
CVE-2023-29011
GitHub: CVE-2023-29011 The config file of `connect.exe` is susceptible to malicious placing
CVE-2023-29007
GitHub: CVE-2023-29007 Arbitrary configuration injection via `git submodule deinit`
CVE-2023-28938
Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentially enable denial of service via local access.
CVE-2023-28866
In the Linux kernel through 6.2.8 net/bluetooth/hci_sync.c allows out-of-bounds access because amp_init1[] and amp_init2[] are supposed to have an intentionally invalid element but do not.
CVE-2023-28856
CVE-2023-28772
An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow.
CVE-2023-28746
Intel: CVE-2023-28746 Register File Data Sampling (RFDS)
CVE-2023-28736
Buffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2023-28642
AppArmor bypass with symlinked /proc in runc
CVE-2023-28625
mod_auth_openidc core dump when OIDCStripCookies is set and an empty Cookie header is supplied
CVE-2023-2861
CVE-2023-28617
org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters.
CVE-2023-2860
Out-of-bounds read when setting hmac data
CVE-2023-28531
ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9.
CVE-2023-28487
Sudo before 1.9.13 does not escape control characters in sudoreplay output.
CVE-2023-28486
Sudo before 1.9.13 does not escape control characters in log messages.
CVE-2023-28484
CVE-2023-28466
CVE-2023-28464
hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation.
CVE-2023-28450
An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-29011 GitHub: CVE-2023-29011 The config file of `connect.exe` is susceptible to malicious placing | 0% Низкий | около 3 лет назад | ||
CVE-2023-29007 GitHub: CVE-2023-29007 Arbitrary configuration injection via `git submodule deinit` | 6% Низкий | около 3 лет назад | ||
CVE-2023-28938 Uncontrolled resource consumption in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a priviledged user to potentially enable denial of service via local access. | CVSS3: 3.4 | 0% Низкий | около 2 лет назад | |
CVE-2023-28866 In the Linux kernel through 6.2.8 net/bluetooth/hci_sync.c allows out-of-bounds access because amp_init1[] and amp_init2[] are supposed to have an intentionally invalid element but do not. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | ||
CVE-2023-28772 An issue was discovered in the Linux kernel before 5.13.3. lib/seq_buf.c has a seq_buf_putmem_hex buffer overflow. | CVSS3: 6.7 | 1% Низкий | больше 3 лет назад | |
CVE-2023-28746 Intel: CVE-2023-28746 Register File Data Sampling (RFDS) | 1% Низкий | больше 2 лет назад | ||
CVE-2023-28736 Buffer overflow in some Intel(R) SSD Tools software before version mdadm-4.2-rc2 may allow a privileged user to potentially enable escalation of privilege via local access. | CVSS3: 6.7 | 0% Низкий | больше 1 года назад | |
CVE-2023-28642 AppArmor bypass with symlinked /proc in runc | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-28625 mod_auth_openidc core dump when OIDCStripCookies is set and an empty Cookie header is supplied | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
CVSS3: 7.1 | 0% Низкий | почти 2 года назад | ||
CVE-2023-28617 org-babel-execute:latex in ob-latex.el in Org Mode through 9.6.1 for GNU Emacs allows attackers to execute arbitrary commands via a file name or directory name that contains shell metacharacters. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-2860 Out-of-bounds read when setting hmac data | CVSS3: 4.4 | 0% Низкий | около 3 лет назад | |
CVE-2023-28531 ssh-add in OpenSSH before 9.3 adds smartcard keys to ssh-agent without the intended per-hop destination constraints. The earliest affected version is 8.9. | CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | |
CVE-2023-28487 Sudo before 1.9.13 does not escape control characters in sudoreplay output. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVE-2023-28486 Sudo before 1.9.13 does not escape control characters in log messages. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | ||
CVSS3: 7 | 0% Низкий | больше 3 лет назад | ||
CVE-2023-28464 hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escalation. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-28450 An issue was discovered in Dnsmasq before 2.90. The default maximum EDNS.0 UDP packet size was set to 4096 but should be 1232 because of DNS Flag Day 2020. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу