CVE-2023-4911
- EPSS 78.36%
- Published 03.10.2023 18:15:10
- Last modified 06.05.2025 21:02:34
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launch...
CVE-2023-4732
- EPSS 0.01%
- Published 03.10.2023 17:15:09
- Last modified 21.11.2024 08:35:51
A flaw was found in pfn_swap_entry_to_page in memory management subsystem in the Linux Kernel. In this flaw, an attacker with a local user privilege may cause a denial of service problem due to a BUG statement referencing pmd_t x.
CVE-2023-5157
- EPSS 0.27%
- Published 27.09.2023 15:19:41
- Last modified 01.10.2025 15:15:41
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
CVE-2023-4806
- EPSS 1.9%
- Published 18.09.2023 17:15:55
- Last modified 26.09.2025 12:15:32
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethos...
CVE-2023-4527
- EPSS 0.11%
- Published 18.09.2023 17:15:55
- Last modified 24.06.2025 17:31:20
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack con...
CVE-2023-4042
- EPSS 0.03%
- Published 23.08.2023 13:15:07
- Last modified 21.11.2024 08:34:17
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
CVE-2023-3899
- EPSS 0.03%
- Published 23.08.2023 11:15:07
- Last modified 21.11.2024 08:18:19
A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the reg...
- EPSS 94.43%
- Published 16.09.2021 15:15:07
- Last modified 16.05.2025 15:27:13
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
CVE-2019-6470
- EPSS 0.27%
- Published 01.11.2019 23:15:10
- Last modified 11.04.2025 14:55:14
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function...
CVE-2019-11043
- EPSS 94.11%
- Published 28.10.2019 15:15:13
- Last modified 14.02.2025 16:43:36
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the p...