CVE-2023-4236
- EPSS 0.18%
- Veröffentlicht 20.09.2023 13:15:12
- Zuletzt bearbeitet 21.11.2024 08:34:41
A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This iss...
CVE-2023-3341
- EPSS 0.25%
- Veröffentlicht 20.09.2023 13:15:11
- Zuletzt bearbeitet 02.12.2025 21:15:51
The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-p...
CVE-2023-41900
- EPSS 0.13%
- Veröffentlicht 15.09.2023 21:15:11
- Zuletzt bearbeitet 21.11.2024 08:21:53
Jetty is a Java based web server and servlet engine. Versions 9.4.21 through 9.4.51, 10.0.15, and 11.0.15 are vulnerable to weak authentication. If a Jetty `OpenIdAuthenticator` uses the optional nested `LoginService`, and that `LoginService` decides...
CVE-2023-40167
- EPSS 4.83%
- Veröffentlicht 15.09.2023 20:15:09
- Zuletzt bearbeitet 21.11.2024 08:18:54
Jetty is a Java based web server and servlet engine. Prior to versions 9.4.52, 10.0.16, 11.0.16, and 12.0.1, Jetty accepts the `+` character proceeding the content-length value in a HTTP/1 header field. This is more permissive than allowed by the RF...
CVE-2023-36479
- EPSS 1.38%
- Veröffentlicht 15.09.2023 19:15:08
- Zuletzt bearbeitet 27.05.2025 21:20:37
Eclipse Jetty Canonical Repository is the canonical repository for the Jetty project. Users of the CgiServlet with a very specific command structure may have the wrong command executed. If a user sends a request to a org.eclipse.jetty.servlets.CGI Se...
CVE-2023-4908
- EPSS 0.27%
- Veröffentlicht 12.09.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:36:14
Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-4909
- EPSS 0.27%
- Veröffentlicht 12.09.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:36:14
Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-4900
- EPSS 0.27%
- Veröffentlicht 12.09.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:36:13
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-4901
- EPSS 0.27%
- Veröffentlicht 12.09.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:36:13
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-4902
- EPSS 0.27%
- Veröffentlicht 12.09.2023 21:15:08
- Zuletzt bearbeitet 21.11.2024 08:36:13
Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)