Количество 26 091
Количество 26 091
CVE-2023-25136
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
CVE-2023-25012
The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long.
CVE-2023-24955
Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2023-24954
Microsoft SharePoint Server Information Disclosure Vulnerability
CVE-2023-24953
Microsoft Excel Remote Code Execution Vulnerability
CVE-2023-24950
Microsoft SharePoint Server Spoofing Vulnerability
CVE-2023-24949
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-24948
Windows Bluetooth Driver Elevation of Privilege Vulnerability
CVE-2023-24947
Windows Bluetooth Driver Remote Code Execution Vulnerability
CVE-2023-24946
Windows Backup Service Elevation of Privilege Vulnerability
CVE-2023-24945
Windows iSCSI Target Service Information Disclosure Vulnerability
CVE-2023-24944
Windows Bluetooth Driver Information Disclosure Vulnerability
CVE-2023-24943
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
CVE-2023-24942
Remote Procedure Call Runtime Denial of Service Vulnerability
CVE-2023-24941
Windows Network File System Remote Code Execution Vulnerability
CVE-2023-24940
Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability
CVE-2023-24939
Server for NFS Denial of Service Vulnerability
CVE-2023-24938
Windows CryptoAPI Denial of Service Vulnerability
CVE-2023-24937
Windows CryptoAPI Denial of Service Vulnerability
CVE-2023-24936
.NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-25136 OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible." | CVSS3: 6.5 | 90% Высокий | 11 месяцев назад | |
CVE-2023-25012 The Linux kernel through 6.1.9 has a Use-After-Free in bigben_remove in drivers/hid/hid-bigbenff.c via a crafted USB device because the LED controllers remain registered for too long. | CVSS3: 4.6 | 1% Низкий | больше 3 лет назад | |
CVE-2023-24955 Microsoft SharePoint Server Remote Code Execution Vulnerability | CVSS3: 7.2 | 85% Высокий | больше 3 лет назад | |
CVE-2023-24954 Microsoft SharePoint Server Information Disclosure Vulnerability | CVSS3: 6.5 | 2% Низкий | больше 3 лет назад | |
CVE-2023-24953 Microsoft Excel Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2023-24950 Microsoft SharePoint Server Spoofing Vulnerability | CVSS3: 6.5 | 67% Средний | больше 3 лет назад | |
CVE-2023-24949 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 25% Средний | больше 3 лет назад | |
CVE-2023-24948 Windows Bluetooth Driver Elevation of Privilege Vulnerability | CVSS3: 7.4 | 1% Низкий | больше 3 лет назад | |
CVE-2023-24947 Windows Bluetooth Driver Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
CVE-2023-24946 Windows Backup Service Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-24945 Windows iSCSI Target Service Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
CVE-2023-24944 Windows Bluetooth Driver Information Disclosure Vulnerability | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2023-24943 Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability | CVSS3: 9.8 | 5% Низкий | больше 3 лет назад | |
CVE-2023-24942 Remote Procedure Call Runtime Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
CVE-2023-24941 Windows Network File System Remote Code Execution Vulnerability | CVSS3: 9.8 | 95% Критический | больше 3 лет назад | |
CVE-2023-24940 Windows Pragmatic General Multicast (PGM) Denial of Service Vulnerability | CVSS3: 7.5 | 5% Низкий | больше 3 лет назад | |
CVE-2023-24939 Server for NFS Denial of Service Vulnerability | CVSS3: 7.5 | 5% Низкий | больше 3 лет назад | |
CVE-2023-24938 Windows CryptoAPI Denial of Service Vulnerability | CVSS3: 6.5 | 2% Низкий | около 3 лет назад | |
CVE-2023-24937 Windows CryptoAPI Denial of Service Vulnerability | CVSS3: 6.5 | 2% Низкий | около 3 лет назад | |
CVE-2023-24936 .NET, .NET Framework, and Visual Studio Elevation of Privilege Vulnerability | CVSS3: 7.5 | 2% Низкий | почти 3 года назад |
Уязвимостей на страницу