CVE-2023-5186
- EPSS 1.54%
- Veröffentlicht 28.09.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:41:15
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: H...
CVE-2023-5187
- EPSS 0.28%
- Veröffentlicht 28.09.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:41:15
Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-5217
- EPSS 1.8%
- Veröffentlicht 28.09.2023 16:15:10
- Zuletzt bearbeitet 03.04.2025 18:55:36
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-42756
- EPSS 0.01%
- Veröffentlicht 28.09.2023 14:15:21
- Zuletzt bearbeitet 21.11.2024 08:23:06
A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash...
CVE-2023-5169
- EPSS 0.32%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 21.11.2024 08:41:13
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115...
CVE-2023-5171
- EPSS 0.32%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 21.11.2024 08:41:13
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and...
CVE-2023-5176
- EPSS 0.67%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 01.05.2025 18:15:52
Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vu...
CVE-2023-41074
- EPSS 1.12%
- Veröffentlicht 27.09.2023 15:19:26
- Zuletzt bearbeitet 21.11.2024 08:20:30
The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.
CVE-2023-42753
- EPSS 0.01%
- Veröffentlicht 25.09.2023 21:15:15
- Zuletzt bearbeitet 21.11.2024 08:23:06
An array indexing vulnerability was found in the netfilter subsystem of the Linux kernel. A missing macro could lead to a miscalculation of the `h->nets` array offset, providing attackers with the primitive to arbitrarily increment/decrement a memory...
CVE-2023-3550
- EPSS 0.09%
- Veröffentlicht 25.09.2023 16:15:14
- Zuletzt bearbeitet 13.02.2025 17:16:57
Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a m...