CVE-2023-52356
- EPSS 0.37%
- Veröffentlicht 25.01.2024 20:15:39
- Zuletzt bearbeitet 10.12.2025 19:16:13
A segment fault (SEGV) flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFReadRGBATileExt() API. This flaw allows a remote attacker to cause a heap-buffer overflow, leading to a denial of service.
CVE-2023-52355
- EPSS 0.38%
- Veröffentlicht 25.01.2024 20:15:38
- Zuletzt bearbeitet 10.12.2025 19:16:12
An out-of-memory flaw was found in libtiff that could be triggered by passing a crafted tiff file to the TIFFRasterScanlineSize64() API. This flaw allows a remote attacker to cause a denial of service via a crafted input with a size smaller than 379 ...
CVE-2023-40547
- EPSS 3.47%
- Veröffentlicht 25.01.2024 16:15:07
- Zuletzt bearbeitet 21.11.2024 08:19:41
A remote code execution vulnerability was found in Shim. The Shim boot support trusts attacker-controlled values when parsing an HTTP response. This flaw allows an attacker to craft a specific malicious HTTP request, leading to a completely controlle...
CVE-2024-0775
- EPSS 0.02%
- Veröffentlicht 22.01.2024 13:15:25
- Zuletzt bearbeitet 21.11.2024 08:47:20
A use-after-free flaw was found in the __ext4_remount in fs/ext4/super.c in ext4 in the Linux kernel. This flaw allows a local user to cause an information leak problem while freeing the old quota file names before a potential failure, leading to a u...
- EPSS 0.01%
- Veröffentlicht 21.01.2024 10:15:07
- Zuletzt bearbeitet 04.11.2025 19:16:24
A use-after-free flaw was found in the Linux Kernel due to a race problem in the unix garbage collector's deletion of SKB races with unix_stream_read_generic() on the socket that the SKB is queued on.
CVE-2024-0408
- EPSS 0.02%
- Veröffentlicht 18.01.2024 16:15:08
- Zuletzt bearbeitet 29.08.2025 13:42:30
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another r...
CVE-2024-0409
- EPSS 0.02%
- Veröffentlicht 18.01.2024 16:15:08
- Zuletzt bearbeitet 29.08.2025 13:42:30
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX contex...
CVE-2024-0607
- EPSS 0.02%
- Veröffentlicht 18.01.2024 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:46:59
A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is an array of...
CVE-2024-0641
- EPSS 0.01%
- Veröffentlicht 17.01.2024 16:15:47
- Zuletzt bearbeitet 21.11.2024 08:47:03
A denial of service vulnerability was found in tipc_crypto_key_revoke in net/tipc/crypto.c in the Linux kernel’s TIPC subsystem. This flaw allows guests with local user privileges to trigger a deadlock and potentially crash the system.
CVE-2024-0646
- EPSS 0.02%
- Veröffentlicht 17.01.2024 16:15:47
- Zuletzt bearbeitet 25.11.2024 10:44:03
An out-of-bounds memory write flaw was found in the Linux kernel’s Transport Layer Security functionality in how a user calls a function splice with a ktls socket as the destination. This flaw allows a local user to crash or potentially escalate thei...