CVE-2022-24805
- EPSS 0.48%
- Veröffentlicht 16.04.2024 20:15:07
- Zuletzt bearbeitet 17.01.2025 16:04:56
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a buffer overflow in the handling of the `INDEX` of `NET-SNMP-VACM-MIB` can cause an out-of-bounds memory access. A user with read...
CVE-2023-7250
- EPSS 0.05%
- Veröffentlicht 18.03.2024 13:15:06
- Zuletzt bearbeitet 03.11.2025 21:16:03
A flaw was found in iperf, a utility for testing network performance using TCP, UDP, and SCTP. A malicious or malfunctioning client can send less than the expected amount of data to the iperf server, which can cause the server to hang indefinitely wa...
CVE-2024-1488
- EPSS 0.11%
- Veröffentlicht 15.02.2024 05:15:10
- Zuletzt bearbeitet 30.01.2025 22:15:09
A vulnerability was found in Unbound due to incorrect default permissions, allowing any process outside the unbound group to modify the unbound runtime configuration. If a process can connect over localhost to port 8953, it can alter the configuratio...
CVE-2023-6681
- EPSS 0.03%
- Veröffentlicht 12.02.2024 14:15:08
- Zuletzt bearbeitet 21.11.2024 08:44:20
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. This issue can result in a large amount of computati...
CVE-2023-5992
- EPSS 0.28%
- Veröffentlicht 31.01.2024 14:15:48
- Zuletzt bearbeitet 03.11.2025 22:16:32
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
CVE-2023-4641
- EPSS 0.02%
- Veröffentlicht 27.12.2023 16:15:13
- Zuletzt bearbeitet 03.11.2025 20:16:05
A flaw was found in shadow-utils. When asking for a new password, shadow-utils asks the password twice. If the password fails on the second attempt, shadow-utils fails in cleaning the buffer used to store the first entry. This may allow an attacker w...
CVE-2023-5870
- EPSS 0.64%
- Veröffentlicht 10.12.2023 18:15:07
- Zuletzt bearbeitet 04.11.2025 20:17:14
A flaw was found in PostgreSQL involving the pg_cancel_backend role that signals background workers, including the logical replication launcher, autovacuum workers, and the autovacuum launcher. Successful exploitation requires a non-core extension wi...
CVE-2023-5869
- EPSS 1.65%
- Veröffentlicht 10.12.2023 18:15:07
- Zuletzt bearbeitet 04.11.2025 20:17:13
A flaw was found in PostgreSQL that allows authenticated database users to execute arbitrary code through missing overflow checks during SQL array value modification. This issue exists due to an integer overflow during array modification where a remo...
CVE-2023-5868
- EPSS 2.79%
- Veröffentlicht 10.12.2023 18:15:07
- Zuletzt bearbeitet 04.11.2025 20:17:13
A memory disclosure vulnerability was found in PostgreSQL that allows remote users to access sensitive information by exploiting certain aggregate function calls with 'unknown'-type arguments. Handling 'unknown'-type values from string literals witho...
CVE-2023-46847
- EPSS 38.21%
- Veröffentlicht 03.11.2023 08:15:08
- Zuletzt bearbeitet 21.11.2024 08:29:25
Squid is vulnerable to a Denial of Service, where a remote attacker can perform buffer overflow attack by writing up to 2 MB of arbitrary data to heap memory when Squid is configured to accept HTTP Digest Authentication.