Количество 26 091
Количество 26 091
CVE-2023-23916
CVE-2023-23915
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS.
CVE-2023-23914
A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on.
CVE-2023-23618
GitHub: CVE-2023-23618 Git for Windows Remote Code Execution Vulnerability
CVE-2023-23604
A duplicate <code>SystemPrincipal</code> object could be created when parsing a non-system html document via <code>DOMParser::ParseFromSafeString</code>. This could have lead to bypassing web security checks. This vulnerability affects Firefox < 109.
CVE-2023-23597
Logic bug in process allocation allowed to read arbitrary files
CVE-2023-23559
In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5 there is an integer overflow in an addition.
CVE-2023-23455
atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).
CVE-2023-23454
cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results).
CVE-2023-23423
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-23422
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-23421
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-23420
Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-23419
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2023-23418
Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability
CVE-2023-23417
Windows Partition Management Driver Elevation of Privilege Vulnerability
CVE-2023-23416
Windows Cryptographic Services Remote Code Execution Vulnerability
CVE-2023-23415
Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability
CVE-2023-23414
Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability
CVE-2023-23413
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS3: 6.5 | 2% Низкий | больше 3 лет назад | ||
CVE-2023-23915 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality to behave incorrectly when multiple URLs are requested in parallel. Using its HSTS support curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even when HTTP is provided in the URL. This HSTS mechanism would however surprisingly fail when multiple transfers are done in parallel as the HSTS cache file gets overwritten by the most recentlycompleted transfer. A later HTTP-only transfer to the earlier host name would then *not* get upgraded properly to HSTS. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
CVE-2023-23914 A cleartext transmission of sensitive information vulnerability exists in curl <v7.88.0 that could cause HSTS functionality fail when multiple URLs are requested serially. Using its HSTS support curl can be instructed to use HTTPS instead of usingan insecure clear-text HTTP step even when HTTP is provided in the URL. ThisHSTS mechanism would however surprisingly be ignored by subsequent transferswhen done on the same command line because the state would not be properlycarried on. | CVSS3: 9.1 | 1% Низкий | 6 месяцев назад | |
CVE-2023-23618 GitHub: CVE-2023-23618 Git for Windows Remote Code Execution Vulnerability | 0% Низкий | больше 3 лет назад | ||
CVE-2023-23604 A duplicate <code>SystemPrincipal</code> object could be created when parsing a non-system html document via <code>DOMParser::ParseFromSafeString</code>. This could have lead to bypassing web security checks. This vulnerability affects Firefox < 109. | 0% Низкий | 12 месяцев назад | ||
CVE-2023-23597 Logic bug in process allocation allowed to read arbitrary files | 0% Низкий | 12 месяцев назад | ||
CVE-2023-23559 In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5 there is an integer overflow in an addition. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-23455 atm_tc_enqueue in net/sched/sch_atm.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results). | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVE-2023-23454 cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can sometimes indicate a TC_ACT_SHOT condition rather than valid classification results). | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVE-2023-23423 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2023-23422 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2023-23421 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2023-23420 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
CVE-2023-23419 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-23418 Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-23417 Windows Partition Management Driver Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
CVE-2023-23416 Windows Cryptographic Services Remote Code Execution Vulnerability | CVSS3: 7.8 | 8% Низкий | больше 3 лет назад | |
CVE-2023-23415 Internet Control Message Protocol (ICMP) Remote Code Execution Vulnerability | CVSS3: 9.8 | 3% Низкий | больше 3 лет назад | |
CVE-2023-23414 Windows Point-to-Point Protocol over Ethernet (PPPoE) Remote Code Execution Vulnerability | CVSS3: 7.1 | 0% Низкий | больше 3 лет назад | |
CVE-2023-23413 Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу