CVE-2023-27536
- EPSS 0.01%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 14.02.2025 16:15:33
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION opt...
CVE-2023-27538
- EPSS 0.01%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 09.06.2025 15:15:29
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previous...
CVE-2022-23121
- EPSS 17.67%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:48:02
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results fr...
CVE-2022-23122
- EPSS 6.77%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:48:02
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results fro...
CVE-2022-23123
- EPSS 2.89%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:48:02
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue resul...
CVE-2022-23124
- EPSS 0.61%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:48:02
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue res...
CVE-2022-23125
- EPSS 22.34%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:48:02
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the copyapplfile function. When parsing the len ...
CVE-2022-0194
- EPSS 8.17%
- Veröffentlicht 28.03.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:38:06
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the ad_addcomment function. The issue results fr...
- EPSS 0.02%
- Veröffentlicht 27.03.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:38:24
In the Linux kernel, pick_next_rt_entity() may return a type confused entry, not detected by the BUG_ON condition, as the confused entry will not be NULL, but list_head.The buggy error condition would lead to a type confused entry with the list head,...
CVE-2023-1380
- EPSS 0.03%
- Veröffentlicht 27.03.2023 21:15:10
- Zuletzt bearbeitet 21.11.2024 07:39:04
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c in the Linux Kernel. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined ...