CVE-2023-3972
- EPSS 0.01%
- Published 01.11.2023 16:15:08
- Last modified 21.11.2024 08:18:25
A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered...
CVE-2023-5633
- EPSS 0.02%
- Published 23.10.2023 22:15:09
- Last modified 21.11.2024 08:42:09
The reference count changes made as part of the CVE-2023-33951 and CVE-2023-33952 fixes exposed a use-after-free flaw in the way memory objects were handled when they were being used to store a surface. When running inside a VMware guest with 3D acce...
CVE-2023-4911
- EPSS 78.36%
- Published 03.10.2023 18:15:10
- Last modified 06.05.2025 21:02:34
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launch...
CVE-2023-5157
- EPSS 0.27%
- Published 27.09.2023 15:19:41
- Last modified 01.10.2025 15:15:41
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
CVE-2023-4527
- EPSS 0.11%
- Published 18.09.2023 17:15:55
- Last modified 24.06.2025 17:31:20
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack con...
CVE-2023-4806
- EPSS 1.9%
- Published 18.09.2023 17:15:55
- Last modified 26.09.2025 12:15:32
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethos...
CVE-2023-4813
- EPSS 0.3%
- Published 12.09.2023 22:15:08
- Last modified 26.09.2025 12:15:34
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database...
CVE-2023-38201
- EPSS 0.02%
- Published 25.08.2023 17:15:08
- Last modified 21.11.2024 08:13:04
A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if the fake age...
CVE-2023-3899
- EPSS 0.03%
- Published 23.08.2023 11:15:07
- Last modified 21.11.2024 08:18:19
A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the reg...
CVE-2023-4147
- EPSS 0.15%
- Published 07.08.2023 14:15:11
- Last modified 21.11.2024 08:34:28
A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the system.