Количество 26 091
Количество 26 091
CVE-2023-23004
In the Linux kernel before 5.19 drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error case whereas it is actually an error pointer).
CVE-2023-23003
In the Linux kernel before 5.16 tools/perf/util/expr.c lacks a check for the hashmap__new return value.
CVE-2023-23002
In the Linux kernel before 5.16.3 drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to be NULL in the error case whereas it is actually an error pointer).
CVE-2023-23001
In the Linux kernel before 5.16.3 drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects it to be NULL in the error case whereas it is actually an error pointer).
CVE-2023-23000
CVE-2023-22999
CVE-2023-22998
CVE-2023-22997
In the Linux kernel before 6.1.2 kernel/module/decompress.c misinterprets the module_get_next_page return value (expects it to be NULL in the error case whereas it is actually an error pointer).
CVE-2023-22996
CVE-2023-22995
CVE-2023-22895
The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product.
CVE-2023-22809
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
CVE-2023-22795
CVE-2023-22745
Buffer Overlow in TSS2_RC_Decode in tpm2-tss
CVE-2023-22743
GitHub: CVE-2023-22743 Git for Windows Installer Elevation of Privilege Vulnerability
CVE-2023-22742
CVE-2023-2253
CVE-2023-22490
GitHub: CVE-2023-22490 mingit Information Disclosure Vulnerability
CVE-2023-2248
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was the duplicate of CVE-2023-31436.
CVE-2023-22466
Tokio's reject_remote_clients configuration may get dropped when creating a Windows named pipe
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-23004 In the Linux kernel before 5.19 drivers/gpu/drm/arm/malidp_planes.c misinterprets the get_sg_table return value (expects it to be NULL in the error case whereas it is actually an error pointer). | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVE-2023-23003 In the Linux kernel before 5.16 tools/perf/util/expr.c lacks a check for the hashmap__new return value. | CVSS3: 4 | 0% Низкий | больше 3 лет назад | |
CVE-2023-23002 In the Linux kernel before 5.16.3 drivers/bluetooth/hci_qca.c misinterprets the devm_gpiod_get_index_optional return value (expects it to be NULL in the error case whereas it is actually an error pointer). | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVE-2023-23001 In the Linux kernel before 5.16.3 drivers/scsi/ufs/ufs-mediatek.c misinterprets the regulator_get return value (expects it to be NULL in the error case whereas it is actually an error pointer). | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | ||
CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | ||
CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | ||
CVE-2023-22997 In the Linux kernel before 6.1.2 kernel/module/decompress.c misinterprets the module_get_next_page return value (expects it to be NULL in the error case whereas it is actually an error pointer). | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | ||
CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | ||
CVE-2023-22895 The bzip2 crate before 0.4.4 for Rust allow attackers to cause a denial of service via a large file that triggers an integer overflow in mem.rs. NOTE: this is unrelated to the https://crates.io/crates/bzip2-rs product. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
CVE-2023-22809 In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value. | CVSS3: 7.8 | 55% Средний | 11 месяцев назад | |
CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | ||
CVE-2023-22745 Buffer Overlow in TSS2_RC_Decode in tpm2-tss | CVSS3: 6.4 | 1% Низкий | больше 3 лет назад | |
CVE-2023-22743 GitHub: CVE-2023-22743 Git for Windows Installer Elevation of Privilege Vulnerability | 0% Низкий | больше 3 лет назад | ||
CVSS3: 5.9 | 1% Низкий | около 2 лет назад | ||
CVSS3: 6.5 | 1% Низкий | около 3 лет назад | ||
CVE-2023-22490 GitHub: CVE-2023-22490 mingit Information Disclosure Vulnerability | 1% Низкий | больше 3 лет назад | ||
CVE-2023-2248 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it was the duplicate of CVE-2023-31436. | 11 месяцев назад | |||
CVE-2023-22466 Tokio's reject_remote_clients configuration may get dropped when creating a Windows named pipe | CVSS3: 5.4 | 1% Низкий | 6 месяцев назад |
Уязвимостей на страницу