Количество 26 124
Количество 26 124
CVE-2023-2650
CVE-2023-26484
CVE-2023-26463
CVE-2023-26253
CVE-2023-26242
afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow.
CVE-2023-26159
Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site potentially leading to information disclosure phishing attacks or other security breaches.
CVE-2023-26136
Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
CVE-2023-2610
Integer Overflow or Wraparound in vim/vim
CVE-2023-2609
NULL Pointer Dereference in vim/vim
CVE-2023-2603
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
CVE-2023-2602
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error which can exhaust the process memory.
CVE-2023-2598
A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation.
CVE-2023-25815
GitHub: CVE-2023-25815 Git looks for localized messages in an unprivileged place
CVE-2023-25809
rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc
CVE-2023-25801
TensorFlow has double free in Fractional(Max/Avg)Pool
CVE-2023-25761
Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.
CVE-2023-25741
When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.
CVE-2023-25731
Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.
CVE-2023-25725
CVE-2023-25690
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS3: 6.5 | 75% Высокий | около 3 лет назад | ||
CVSS3: 8.2 | 1% Низкий | около 2 лет назад | ||
CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | ||
CVSS3: 7.5 | 1% Низкий | почти 2 года назад | ||
CVE-2023-26242 afu_mmio_region_get_by_offset in drivers/fpga/dfl-afu-region.c in the Linux kernel through 6.1.12 has an integer overflow. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-26159 Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site potentially leading to information disclosure phishing attacks or other security breaches. | CVSS3: 6.1 | 1% Низкий | 6 месяцев назад | |
CVE-2023-26136 Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized. | 3% Низкий | 12 месяцев назад | ||
CVE-2023-2610 Integer Overflow or Wraparound in vim/vim | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-2609 NULL Pointer Dereference in vim/vim | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
CVE-2023-2603 A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB. | CVSS3: 7.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-2602 A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error which can exhaust the process memory. | CVSS3: 3.3 | 0% Низкий | около 3 лет назад | |
CVE-2023-2598 A flaw was found in the fixed buffer registration code for io_uring (io_sqe_buffer_register in io_uring/rsrc.c) in the Linux kernel that allows out-of-bounds access to physical memory beyond the end of the buffer. This flaw enables full local privilege escalation. | CVSS3: 7.8 | 1% Низкий | около 3 лет назад | |
CVE-2023-25815 GitHub: CVE-2023-25815 Git looks for localized messages in an unprivileged place | 1% Низкий | около 3 лет назад | ||
CVE-2023-25809 rootless: `/sys/fs/cgroup` is writable when cgroupns isn't unshared in runc | CVSS3: 6.3 | 0% Низкий | больше 3 лет назад | |
CVE-2023-25801 TensorFlow has double free in Fractional(Max/Avg)Pool | CVSS3: 7.8 | 0% Низкий | около 2 лет назад | |
CVE-2023-25761 Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin. | CVSS3: 5.4 | 1% Низкий | 11 месяцев назад | |
CVE-2023-25741 When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110. | 1% Низкий | 12 месяцев назад | ||
CVE-2023-25731 Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110. | 1% Низкий | 12 месяцев назад | ||
CVSS3: 9.1 | 5% Низкий | больше 3 лет назад | ||
CVE-2023-25690 Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy | CVSS3: 9.8 | 85% Высокий | больше 3 лет назад |
Уязвимостей на страницу