- EPSS 0.08%
- Published 27.10.2023 05:15:39
- Last modified 06.03.2025 16:15:42
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
CVE-2023-34058
- EPSS 0.03%
- Published 27.10.2023 05:15:38
- Last modified 06.03.2025 16:15:41
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a...
CVE-2023-46234
- EPSS 0.35%
- Published 26.10.2023 15:15:09
- Last modified 10.04.2025 20:47:25
browserify-sign is a package to duplicate the functionality of node's crypto public key functions, much of this is based on Fedor Indutny's work on indutny/tls.js. An upper bound check issue in `dsaVerify` function allows an attacker to construct sig...
CVE-2023-5367
- EPSS 0.06%
- Published 25.10.2023 20:15:18
- Last modified 04.08.2025 21:15:27
A out-of-bounds write flaw was found in the xorg-x11-server. This issue occurs due to an incorrect calculation of a buffer offset when copying data stored in the heap in the XIChangeDeviceProperty function in Xi/xiproperty.c and in RRChangeOutputProp...
CVE-2023-5380
- EPSS 0.08%
- Published 25.10.2023 20:15:18
- Last modified 21.11.2024 08:41:39
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a wi...
CVE-2023-41983
- EPSS 1.11%
- Published 25.10.2023 19:15:10
- Last modified 21.11.2024 08:22:02
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service.
CVE-2023-42852
- EPSS 2.17%
- Published 25.10.2023 19:15:10
- Last modified 05.05.2025 15:15:53
A logic issue was addressed with improved checks. This issue is fixed in iOS 17.1 and iPadOS 17.1, watchOS 10.1, iOS 16.7.2 and iPadOS 16.7.2, macOS Sonoma 14.1, Safari 17.1, tvOS 17.1. Processing web content may lead to arbitrary code execution.
CVE-2023-5724
- EPSS 0.77%
- Published 25.10.2023 18:17:44
- Last modified 21.11.2024 08:42:21
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
CVE-2023-5725
- EPSS 0.38%
- Published 25.10.2023 18:17:44
- Last modified 21.11.2024 08:42:21
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
CVE-2023-5728
- EPSS 0.48%
- Published 25.10.2023 18:17:44
- Last modified 21.11.2024 08:42:22
During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.