CVE-2023-38802
- EPSS 0.94%
- Veröffentlicht 29.08.2023 16:15:09
- Zuletzt bearbeitet 21.11.2024 08:14:13
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
CVE-2023-41361
- EPSS 0.38%
- Veröffentlicht 29.08.2023 04:15:17
- Zuletzt bearbeitet 21.11.2024 08:21:09
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
CVE-2023-41358
- EPSS 0.4%
- Veröffentlicht 29.08.2023 04:15:16
- Zuletzt bearbeitet 21.11.2024 08:21:08
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
CVE-2023-41360
- EPSS 0.28%
- Veröffentlicht 29.08.2023 04:15:16
- Zuletzt bearbeitet 21.11.2024 08:21:09
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
CVE-2023-4569
- EPSS 0.01%
- Veröffentlicht 28.08.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 08:35:26
A memory leak flaw was found in nft_set_catchall_flush in net/netfilter/nf_tables_api.c in the Linux Kernel. This issue may allow a local attacker to cause double-deactivations of catchall elements, which can result in a memory leak.
CVE-2020-24165
- EPSS 0.43%
- Veröffentlicht 28.08.2023 21:15:07
- Zuletzt bearbeitet 21.11.2024 05:14:27
An issue was discovered in TCG Accelerator in QEMU 4.2.0, allows local attackers to execute arbitrary code, escalate privileges, and cause a denial of service (DoS). Note: This is disputed as a bug and not a valid security issue by multiple third par...
CVE-2023-41080
- EPSS 13.66%
- Veröffentlicht 25.08.2023 21:15:09
- Zuletzt bearbeitet 07.08.2025 11:15:27
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from ...
CVE-2023-40577
- EPSS 3.58%
- Veröffentlicht 25.08.2023 01:15:09
- Zuletzt bearbeitet 21.11.2024 08:19:45
Alertmanager handles alerts sent by client applications such as the Prometheus server. An attacker with the permission to perform POST requests on the /api/v1/alerts endpoint could be able to execute arbitrary JavaScript code on the users of Promethe...
CVE-2023-4428
- EPSS 10.93%
- Veröffentlicht 23.08.2023 00:15:09
- Zuletzt bearbeitet 01.07.2025 14:15:30
Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
CVE-2023-4429
- EPSS 0.37%
- Veröffentlicht 23.08.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:07
Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)