CVE-2023-4155
- EPSS 0.01%
- Veröffentlicht 13.09.2023 17:15:10
- Zuletzt bearbeitet 21.11.2024 08:34:30
A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEXIT` handler recursively. If an...
CVE-2023-2680
- EPSS 0.03%
- Veröffentlicht 13.09.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 07:59:04
This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm that was actually missing the fix for CVE-2021-3750...
CVE-2023-3255
- EPSS 0.13%
- Veröffentlicht 13.09.2023 17:15:09
- Zuletzt bearbeitet 21.11.2024 08:16:48
A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` function. This could allow a remot...
CVE-2023-4813
- EPSS 0.3%
- Veröffentlicht 12.09.2023 22:15:08
- Zuletzt bearbeitet 26.09.2025 12:15:34
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database...
CVE-2023-4569
- EPSS 0.01%
- Veröffentlicht 28.08.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 08:35:26
A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.
CVE-2023-38201
- EPSS 0.02%
- Veröffentlicht 25.08.2023 17:15:08
- Zuletzt bearbeitet 21.11.2024 08:13:04
A flaw was found in the Keylime registrar that could allow a bypass of the challenge-response protocol during agent registration. This issue may allow an attacker to impersonate an agent and hide the true status of a monitored machine if the fake age...
CVE-2023-4042
- EPSS 0.03%
- Veröffentlicht 23.08.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 08:34:17
A flaw was found in ghostscript. The fix for CVE-2020-16305 in ghostscript was not included in RHSA-2021:1852-06 advisory as it was claimed to be. This issue only affects the ghostscript package as shipped with Red Hat Enterprise Linux 8.
CVE-2023-3899
- EPSS 0.03%
- Veröffentlicht 23.08.2023 11:15:07
- Zuletzt bearbeitet 21.11.2024 08:18:19
A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significant number of methods to all users that could change the state of the reg...
CVE-2023-4459
- EPSS 0.01%
- Veröffentlicht 21.08.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:12
A NULL pointer dereference flaw was found in vmxnet3_rq_cleanup in drivers/net/vmxnet3/vmxnet3_drv.c in the networking sub-component in vmxnet3 in the Linux Kernel. This issue may allow a local attacker with normal user privilege to cause a denial of...
CVE-2023-4387
- EPSS 0.01%
- Veröffentlicht 16.08.2023 19:15:10
- Zuletzt bearbeitet 03.06.2025 03:15:25
A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethernet NIC driver in the Linux Kernel. This issue could allow a local attacker to crash the system due to a double-free while cleani...