CVE-2023-6516
- EPSS 0.19%
- Published 13.02.2024 14:15:46
- Last modified 21.11.2024 08:44:00
To keep its cache database efficient, `named` running as a recursive resolver occasionally attempts to clean up the database. It uses several methods, including some that are asynchronous: a small chunk of memory pointing to the cache element that ca...
CVE-2023-5517
- EPSS 0.16%
- Published 13.02.2024 14:15:45
- Last modified 21.11.2024 08:41:55
A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect <domain>;` is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an a...
CVE-2023-5679
- EPSS 0.16%
- Published 13.02.2024 14:15:45
- Last modified 29.03.2025 00:15:16
A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18...
CVE-2023-5680
- EPSS 0.09%
- Published 13.02.2024 14:15:45
- Last modified 21.11.2024 08:42:15
If a resolver cache has a very large number of ECS records stored for the same name, the process of cleaning the cache database node for this name can significantly impair query performance. This issue affects BIND 9 versions 9.11.3-S1 through 9.11....
CVE-2024-0567
- EPSS 1.3%
- Published 16.01.2024 14:15:48
- Last modified 21.11.2024 08:46:53
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, r...
CVE-2023-31102
- EPSS 35.54%
- Published 03.11.2023 04:15:20
- Last modified 21.11.2024 08:01:25
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
CVE-2023-5178
- EPSS 3.39%
- Published 01.11.2023 17:15:11
- Last modified 21.11.2024 08:41:14
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free prob...
CVE-2023-38545
- EPSS 22.22%
- Published 18.10.2023 04:15:11
- Last modified 13.02.2025 17:16:47
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length th...
CVE-2023-45862
- EPSS 0.02%
- Published 14.10.2023 21:15:45
- Last modified 21.11.2024 08:27:30
An issue was discovered in drivers/usb/storage/ene_ub6250.c for the ENE UB6250 reader driver in the Linux kernel before 6.2.5. An object could potentially extend beyond the end of an allocation.
CVE-2023-40745
- EPSS 0.35%
- Published 05.10.2023 19:15:11
- Last modified 21.11.2024 08:20:03
LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.