CVE-2023-6516
- EPSS 0.19%
- Veröffentlicht 13.02.2024 14:15:46
- Zuletzt bearbeitet 21.11.2024 08:44:00
To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that ca...
CVE-2023-5517
- EPSS 0.16%
- Veröffentlicht 13.02.2024 14:15:45
- Zuletzt bearbeitet 21.11.2024 08:41:55
A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain>;` is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an a...
CVE-2023-5679
- EPSS 0.16%
- Veröffentlicht 13.02.2024 14:15:45
- Zuletzt bearbeitet 29.03.2025 00:15:16
A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18...
CVE-2023-5680
- EPSS 0.09%
- Veröffentlicht 13.02.2024 14:15:45
- Zuletzt bearbeitet 21.11.2024 08:42:15
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11....
CVE-2024-0567
- EPSS 1.3%
- Veröffentlicht 16.01.2024 14:15:48
- Zuletzt bearbeitet 21.11.2024 08:46:53
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, r...
CVE-2023-31102
- EPSS 35.54%
- Veröffentlicht 03.11.2023 04:15:20
- Zuletzt bearbeitet 21.11.2024 08:01:25
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
CVE-2023-5178
- EPSS 3.39%
- Veröffentlicht 01.11.2023 17:15:11
- Zuletzt bearbeitet 21.11.2024 08:41:14
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free prob...
CVE-2023-38545
- EPSS 22.22%
- Veröffentlicht 18.10.2023 04:15:11
- Zuletzt bearbeitet 13.02.2025 17:16:47
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length th...
CVE-2023-45862
- EPSS 0.02%
- Veröffentlicht 14.10.2023 21:15:45
- Zuletzt bearbeitet 21.11.2024 08:27:30
An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before 6.2.5. An object could potentially extend beyond the end of an allocation.
CVE-2023-40745
- EPSS 0.35%
- Veröffentlicht 05.10.2023 19:15:11
- Zuletzt bearbeitet 21.11.2024 08:20:03
LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.