Количество 26 124
Количество 26 124
CVE-2023-2804
Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo
CVE-2023-27986
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90.
CVE-2023-27985
emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90
CVE-2023-27911
AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior
CVE-2023-27910
AutoDesk: CVE-2023-27910 stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior
CVE-2023-27909
AutoDesk: CVE-2023-27909 Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK 2020 or prior
CVE-2023-27579
TensorFlow has Floating Point Exception in TFLite in conv kernel
CVE-2023-27561
runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges related to libcontainer/rootfs_linux.go. To exploit this an attacker must be able to spawn two containers with custom volume-mount configurations and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression.
CVE-2023-27538
CVE-2023-27537
A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks two threads sharing the same HSTS data could end up doing a double-free or use-after-free.
CVE-2023-27536
CVE-2023-27535
CVE-2023-27534
CVE-2023-27533
CVE-2023-27522
Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting
CVE-2023-27478
CVE-2023-27477
CVE-2023-27371
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.
CVE-2023-27320
CVE-2023-2731
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file resulting in a program crash or denial of service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-2804 Red Hat, Inc. CVE-2023-2804: Heap Based Overflow libjpeg-turbo | CVSS3: 6.5 | 1% Низкий | 6 месяцев назад | |
CVE-2023-27986 emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to Emacs Lisp code injections through a crafted mailto: URI with unescaped double-quote characters. It is fixed in 29.0.90. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-27985 emacsclient-mail.desktop in Emacs 28.1 through 28.2 is vulnerable to shell command injections through a crafted mailto: URI. This is related to lack of compliance with the Desktop Entry Specification. It is fixed in 29.0.90 | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2023-27911 AutoDesk: CVE-2023-27911 Heap buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior | CVSS3: 7.8 | 1% Низкий | больше 2 лет назад | |
CVE-2023-27910 AutoDesk: CVE-2023-27910 stack buffer overflow vulnerability in Autodesk® FBX® SDK 2020 or prior | 1% Низкий | около 3 лет назад | ||
CVE-2023-27909 AutoDesk: CVE-2023-27909 Out-Of-Bounds Write Vulnerability in Autodesk® FBX® SDK 2020 or prior | 0% Низкий | около 3 лет назад | ||
CVE-2023-27579 TensorFlow has Floating Point Exception in TFLite in conv kernel | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-27561 runc through 1.1.4 has Incorrect Access Control leading to Escalation of Privileges related to libcontainer/rootfs_linux.go. To exploit this an attacker must be able to spawn two containers with custom volume-mount configurations and be able to run custom images. NOTE: this issue exists because of a CVE-2019-19921 regression. | CVSS3: 7 | 0% Низкий | больше 3 лет назад | |
CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | ||
CVE-2023-27537 A double free vulnerability exists in libcurl <8.0.0 when sharing HSTS data between separate "handles". This sharing was introduced without considerations for do this sharing across separate threads but there was no indication of this fact in the documentation. Due to missing mutexes or thread locks two threads sharing the same HSTS data could end up doing a double-free or use-after-free. | CVSS3: 5.9 | 2% Низкий | 6 месяцев назад | |
CVSS3: 5.9 | 2% Низкий | больше 3 лет назад | ||
CVSS3: 5.9 | 2% Низкий | больше 3 лет назад | ||
CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | ||
CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | ||
CVE-2023-27522 Apache HTTP Server: mod_proxy_uwsgi HTTP response splitting | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
CVSS3: 6.5 | 1% Низкий | около 2 лет назад | ||
CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | ||
CVE-2023-27371 GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function. | CVSS3: 5.9 | 1% Низкий | больше 3 лет назад | |
CVSS3: 7.2 | 2% Низкий | больше 3 лет назад | ||
CVE-2023-2731 A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file resulting in a program crash or denial of service. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу