Количество 26 124
Количество 26 124
CVE-2023-2726
Chromium: CVE-2023-2726 Inappropriate implementation in WebApp Installs
CVE-2023-2725
Chromium: CVE-2023-2725 Use after free in Guest View
CVE-2023-2724
Chromium: CVE-2023-2724 Type Confusion in V8
CVE-2023-2723
Chromium: CVE-2023-2723 Use after free in DevTools
CVE-2023-2722
Chromium: CVE-2023-2722 Use after free in Autofill UI
CVE-2023-2721
Chromium: CVE-2023-2721 Use after free in Navigation
CVE-2023-27119
WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild.
CVE-2023-27043
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python.
CVE-2023-2700
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
CVE-2023-26966
libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian.
CVE-2023-26965
loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image.
CVE-2023-26964
CVE-2023-26917
CVE-2023-26916
CVE-2023-26819
cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}.
CVE-2023-26769
Buffer Overflow vulnerability found in Liblouis Lou_Trace v.3.24.0 allows a remote attacker to cause a denial of service via the resolveSubtable function at compileTranslationTabel.c.
CVE-2023-26768
Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the compileTranslationTable.c and lou_setDataPath functions.
CVE-2023-26767
Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the lou_logFile function at logginc.c endpoint.
CVE-2023-26604
systemd before 247 does not adequately block local privilege escalation for some Sudo configurations e.g. plausible sudoers files in which the "systemctl status" command may be executed. Specifically systemd does not set LESSSECURE to 1 and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo because less executes as root when the terminal size is too small to show the complete systemctl output.
CVE-2023-26545
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-2726 Chromium: CVE-2023-2726 Inappropriate implementation in WebApp Installs | 1% Низкий | около 3 лет назад | ||
CVE-2023-2725 Chromium: CVE-2023-2725 Use after free in Guest View | 25% Средний | около 3 лет назад | ||
CVE-2023-2724 Chromium: CVE-2023-2724 Type Confusion in V8 | 29% Средний | около 3 лет назад | ||
CVE-2023-2723 Chromium: CVE-2023-2723 Use after free in DevTools | 15% Средний | около 3 лет назад | ||
CVE-2023-2722 Chromium: CVE-2023-2722 Use after free in Autofill UI | 1% Низкий | около 3 лет назад | ||
CVE-2023-2721 Chromium: CVE-2023-2721 Use after free in Navigation | 1% Низкий | около 3 лет назад | ||
CVE-2023-27119 WebAssembly v1.0.29 was discovered to contain a segmentation fault via the component wabt::Decompiler::WrapChild. | 0% Низкий | 12 месяцев назад | ||
CVE-2023-27043 The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a specific domain (e.g., only @company.example.com addresses may be used for signup). This occurs in email/_parseaddr.py in recent versions of Python. | CVSS3: 5.3 | 3% Низкий | 8 месяцев назад | |
CVE-2023-2700 A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
CVE-2023-26966 libtiff 4.5.0 is vulnerable to Buffer Overflow in uv_encode() when libtiff reads a corrupted little-endian TIFF file and specifies the output to be big-endian. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-26965 loadImage() in tools/tiffcrop.c in LibTIFF through 4.5.0 has a heap-based use after free via a crafted TIFF image. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVSS3: 7.5 | 1% Низкий | около 3 лет назад | ||
CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | ||
CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | ||
CVE-2023-26819 cJSON 1.7.15 might allow a denial of service via a crafted JSON document such as {"a": true, "b": [ null,9999999999999999999999999999999999999999999999912345678901234567]}. | CVSS3: 2.9 | 0% Низкий | 8 месяцев назад | |
CVE-2023-26769 Buffer Overflow vulnerability found in Liblouis Lou_Trace v.3.24.0 allows a remote attacker to cause a denial of service via the resolveSubtable function at compileTranslationTabel.c. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
CVE-2023-26768 Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the compileTranslationTable.c and lou_setDataPath functions. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
CVE-2023-26767 Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the lou_logFile function at logginc.c endpoint. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
CVE-2023-26604 systemd before 247 does not adequately block local privilege escalation for some Sudo configurations e.g. plausible sudoers files in which the "systemctl status" command may be executed. Specifically systemd does not set LESSSECURE to 1 and thus other programs may be launched from the less program. This presents a substantial security risk when running systemctl from Sudo because less executes as root when the terminal size is too small to show the complete systemctl output. | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVSS3: 4.7 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу