CVE-2023-4156
- EPSS 0.03%
- Published 25.09.2023 18:15:11
- Last modified 21.11.2024 08:34:30
A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.
CVE-2023-5156
- EPSS 0.06%
- Published 25.09.2023 16:15:15
- Last modified 21.11.2024 08:41:10
A flaw was found in the GNU C Library. A recent fix for CVE-2023-4806 introduced the potential for a memory leak, which may result in an application crash.
CVE-2023-4527
- EPSS 0.11%
- Published 18.09.2023 17:15:55
- Last modified 24.06.2025 17:31:20
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack con...
CVE-2023-4806
- EPSS 1.9%
- Published 18.09.2023 17:15:55
- Last modified 26.09.2025 12:15:32
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethos...
CVE-2023-3301
- EPSS 0.01%
- Published 13.09.2023 17:15:10
- Last modified 21.11.2024 08:16:57
A flaw was found in QEMU. The async nature of hot-unplug enables a race scenario where the net device backend is cleared before the virtio-net pci frontend has been unplugged. A malicious guest could use this time window to trigger an assertion and c...
CVE-2023-4155
- EPSS 0.01%
- Published 13.09.2023 17:15:10
- Last modified 21.11.2024 08:34:30
A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEXIT` handler recursively. If an...
CVE-2023-2680
- EPSS 0.03%
- Published 13.09.2023 17:15:09
- Last modified 21.11.2024 07:59:04
This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750...
CVE-2023-3255
- EPSS 0.13%
- Published 13.09.2023 17:15:09
- Last modified 21.11.2024 08:16:48
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remot...
CVE-2023-4813
- EPSS 0.3%
- Published 12.09.2023 22:15:08
- Last modified 26.09.2025 12:15:34
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database...
CVE-2023-4569
- EPSS 0.01%
- Published 28.08.2023 22:15:10
- Last modified 21.11.2024 08:35:26
A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.