CVE-2023-44487
- EPSS 94.42%
- Published 10.10.2023 14:15:10
- Last modified 11.06.2025 17:29:54
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2023-43641
- EPSS 73.66%
- Published 09.10.2023 22:15:12
- Last modified 21.11.2024 08:24:31
libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue sheet from a malicious webpag...
CVE-2023-45363
- EPSS 8.19%
- Published 09.10.2023 05:15:09
- Last modified 21.11.2024 08:26:49
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages re...
CVE-2023-45364
- EPSS 0.09%
- Published 09.10.2023 05:15:09
- Last modified 21.11.2024 08:26:49
An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID bel...
CVE-2023-39928
- EPSS 0.16%
- Published 06.10.2023 16:15:13
- Last modified 21.11.2024 08:16:03
A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a ...
CVE-2023-42755
- EPSS 0.01%
- Published 05.10.2023 19:15:11
- Last modified 21.11.2024 08:23:06
A flaw was found in the IPv4 Resource Reservation Protocol (RSVP) classifier in the Linux kernel. The xprt pointer may go beyond the linear part of the skb, leading to an out-of-bounds read in the `rsvp_classify` function. This issue may allow a loca...
CVE-2023-43804
- EPSS 0.47%
- Published 04.10.2023 17:15:10
- Last modified 13.12.2024 14:15:20
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to spe...
CVE-2023-4911
- EPSS 78.36%
- Published 03.10.2023 18:15:10
- Last modified 06.05.2025 21:02:34
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launch...
CVE-2023-44488
- EPSS 0.82%
- Published 30.09.2023 20:15:10
- Last modified 21.11.2024 08:25:59
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
CVE-2023-43655
- EPSS 2.26%
- Published 29.09.2023 20:15:09
- Last modified 23.04.2025 17:31:40
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_...