CVE-2023-7216
- EPSS 0.18%
- Veröffentlicht 05.02.2024 15:15:08
- Zuletzt bearbeitet 21.11.2024 08:45:32
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside...
CVE-2023-6240
- EPSS 0.07%
- Veröffentlicht 04.02.2024 14:15:47
- Zuletzt bearbeitet 21.11.2024 08:43:26
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
CVE-2023-5992
- EPSS 0.28%
- Veröffentlicht 31.01.2024 14:15:48
- Zuletzt bearbeitet 03.11.2025 22:16:32
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
CVE-2024-0914
- EPSS 0.23%
- Veröffentlicht 31.01.2024 05:15:08
- Zuletzt bearbeitet 21.11.2024 08:47:42
A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the ...
CVE-2024-0564
- EPSS 0.02%
- Veröffentlicht 30.01.2024 15:15:08
- Zuletzt bearbeitet 25.11.2024 09:15:05
A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host ...
CVE-2023-40546
- EPSS 0.03%
- Veröffentlicht 29.01.2024 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:19:41
A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new variable, it tries to print an error message to the user; however, the number of parameters used by the logging function doesn't match ...
CVE-2023-40549
- EPSS 0.03%
- Veröffentlicht 29.01.2024 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:19:42
An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of se...
CVE-2023-40550
- EPSS 0.03%
- Veröffentlicht 29.01.2024 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:19:42
An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase.
CVE-2023-40551
- EPSS 0.02%
- Veröffentlicht 29.01.2024 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:19:42
A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.
CVE-2024-0841
- EPSS 0.01%
- Veröffentlicht 28.01.2024 12:15:52
- Zuletzt bearbeitet 21.11.2024 08:47:29
A null pointer dereference flaw was found in the hugetlbfs_fill_super function in the Linux kernel hugetlbfs (HugeTLB pages) functionality. This issue may allow a local user to crash the system or potentially escalate their privileges on the system.