CVE-2023-4430
- EPSS 13.13%
- Veröffentlicht 23.08.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:08
Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-4431
- EPSS 0.15%
- Veröffentlicht 23.08.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:35:08
Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
CVE-2022-48565
- EPSS 7.27%
- Veröffentlicht 22.08.2023 19:16:32
- Zuletzt bearbeitet 21.11.2024 07:33:30
An XML External Entity (XXE) issue was discovered in Python through 3.9.1. The plistlib module no longer accepts entity declarations in XML plist files to avoid XML vulnerabilities.
CVE-2022-48566
- EPSS 0.1%
- Veröffentlicht 22.08.2023 19:16:32
- Zuletzt bearbeitet 21.11.2024 07:33:31
An issue was discovered in compare_digest in Lib/hmac.py in Python through 3.9.1. Constant-time-defeating optimisations were possible in the accumulator variable in hmac.compare_digest.
CVE-2022-48174
- EPSS 0.68%
- Veröffentlicht 22.08.2023 19:16:31
- Zuletzt bearbeitet 18.12.2025 18:20:59
There is a stack overflow vulnerability in ash.c:6030 in busybox before 1.35. In the environment of Internet of Vehicles, this vulnerability can be executed from command to arbitrary code execution.
CVE-2022-48554
- EPSS 0.02%
- Veröffentlicht 22.08.2023 19:16:31
- Zuletzt bearbeitet 21.11.2024 07:33:30
File before 5.43 has an stack-based buffer over-read in file_copystr in funcs.c. NOTE: "File" is the name of an Open Source project.
CVE-2022-48560
- EPSS 0.21%
- Veröffentlicht 22.08.2023 19:16:31
- Zuletzt bearbeitet 21.11.2024 07:33:30
A use-after-free exists in Python through 3.9 via heappushpop in heapq.
CVE-2022-44729
- EPSS 0.15%
- Veröffentlicht 22.08.2023 19:16:29
- Zuletzt bearbeitet 13.02.2025 17:15:46
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. On version 1.16, a malicious SVG could trigger loading external resources by default, causin...
CVE-2022-44730
- EPSS 0.29%
- Veröffentlicht 22.08.2023 19:16:29
- Zuletzt bearbeitet 13.02.2025 17:15:47
Server-Side Request Forgery (SSRF) vulnerability in Apache Software Foundation Apache XML Graphics Batik.This issue affects Apache XML Graphics Batik: 1.16. A malicious SVG can probe user profile / data and send it directly as parameter to a URL.
CVE-2022-37050
- EPSS 0.06%
- Veröffentlicht 22.08.2023 19:16:23
- Zuletzt bearbeitet 03.11.2025 20:15:55
In Poppler 22.07.0, PDFDoc::savePageAs in PDFDoc.c callows attackers to cause a denial-of-service (application crashes with SIGABRT) by crafting a PDF file in which the xref data structure is mishandled in getCatalog processing. Note that this vulner...