CVE-2024-0567
- EPSS 1.75%
- Veröffentlicht 16.01.2024 14:15:48
- Zuletzt bearbeitet 21.11.2024 08:46:53
A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, r...
CVE-2023-6040
- EPSS 0.02%
- Veröffentlicht 12.01.2024 02:15:44
- Zuletzt bearbeitet 20.03.2025 16:59:40
An out-of-bounds access vulnerability involving netfilter was reported and fixed as: f1082dd31fe4 (netfilter: nf_tables: Reject tables of unsupported family); While creating a new netfilter table, lack of a safeguard against invalid nf_tables family ...
- EPSS 0.02%
- Veröffentlicht 11.01.2024 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:38:47
An issue was discovered in the Linux kernel before 6.6.8. do_vcc_ioctl in net/atm/ioctl.c has a use-after-free because of a vcc_recvmsg race condition.
- EPSS 0.02%
- Veröffentlicht 11.01.2024 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:38:47
An issue was discovered in the Linux kernel before 6.6.8. atalk_ioctl in net/appletalk/ddp.c has a use-after-free because of an atalk_recvmsg race condition.
- EPSS 0.02%
- Veröffentlicht 11.01.2024 19:15:12
- Zuletzt bearbeitet 21.11.2024 08:38:47
An issue was discovered in the Linux kernel before 6.6.8. rose_ioctl in net/rose/af_rose.c has a use-after-free because of a rose_accept race condition.
CVE-2024-22049
- EPSS 1.19%
- Veröffentlicht 04.01.2024 21:15:10
- Zuletzt bearbeitet 07.01.2026 19:49:03
httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled file...
- EPSS 0.02%
- Veröffentlicht 04.01.2024 17:15:08
- Zuletzt bearbeitet 30.08.2025 09:15:31
A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the ac...
CVE-2023-7101
- EPSS 83.31%
- Veröffentlicht 24.12.2023 22:15:07
- Zuletzt bearbeitet 24.10.2025 16:39:52
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Speci...
CVE-2023-51714
- EPSS 0.13%
- Veröffentlicht 24.12.2023 21:15:25
- Zuletzt bearbeitet 20.03.2025 21:31:13
An issue was discovered in the HTTP2 implementation in Qt before 5.15.17, 6.x before 6.2.11, 6.3.x through 6.5.x before 6.5.4, and 6.6.x before 6.6.2. network/access/http2/hpacktable.cpp has an incorrect HPack integer overflow check.
CVE-2023-51766
- EPSS 1.64%
- Veröffentlicht 24.12.2023 06:15:07
- Zuletzt bearbeitet 04.11.2025 19:16:21
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mecha...