CVE-2023-22008
- EPSS 0.04%
- Published 18.07.2023 21:15:12
- Last modified 21.11.2024 07:44:05
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to ...
CVE-2023-22005
- EPSS 0.04%
- Published 18.07.2023 21:15:11
- Last modified 21.11.2024 07:44:05
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multipl...
CVE-2023-3338
- EPSS 9.01%
- Published 30.06.2023 22:15:10
- Last modified 21.11.2024 08:17:02
A null pointer dereference flaw was found in the Linux kernel's DECnet networking protocol. This issue could allow a remote user to crash the system.
CVE-2023-2828
- EPSS 0.87%
- Published 21.06.2023 17:15:47
- Last modified 21.11.2024 07:59:22
Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can be configured using the `max-ca...
CVE-2023-2829
- EPSS 0.07%
- Published 21.06.2023 17:15:47
- Last modified 21.11.2024 07:59:22
A `named` instance configured to run as a DNSSEC-validating recursive resolver with the Aggressive Use of DNSSEC-Validated Cache (RFC 8198) option (`synth-from-dnssec`) enabled can be remotely terminated using a zone with a malformed NSEC record. Thi...
CVE-2023-2911
- EPSS 0.29%
- Published 21.06.2023 17:15:47
- Last modified 21.11.2024 07:59:33
If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop and terminate unexpectedly du...
CVE-2023-2953
- EPSS 1.11%
- Published 30.05.2023 22:15:10
- Last modified 10.01.2025 22:15:23
A vulnerability was found in openldap. This security flaw causes a null pointer dereference in ber_memalloc_x() function.
CVE-2023-0045
- EPSS 0.25%
- Published 25.04.2023 23:15:09
- Last modified 13.02.2025 17:15:52
The current implementation of the prctl syscall does not issue an IBPB immediately during the syscall. The ib_prctl_set function updates the Thread Information Flags (TIFs) for the task and updates the SPEC_CTRL MSR on the function __speculation_ctr...
CVE-2023-20862
- EPSS 0.37%
- Published 19.04.2023 20:15:10
- Last modified 05.02.2025 16:15:33
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to exp...
CVE-2023-27043
- EPSS 0.11%
- Published 19.04.2023 00:15:07
- Last modified 19.05.2025 12:38:20
The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protect...