CVE-2023-39945
- EPSS 0.11%
- Veröffentlicht 11.08.2023 14:15:13
- Zuletzt bearbeitet 21.11.2024 08:16:05
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5, a data submessage sent to PDP port raises unhandled `BadParamException` in fastcdr...
CVE-2023-39946
- EPSS 0.11%
- Veröffentlicht 11.08.2023 14:15:13
- Zuletzt bearbeitet 21.11.2024 08:16:05
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, heap can be overflowed by providing a PID_PROPERTY_LIST parameter that contains a ...
CVE-2023-39947
- EPSS 0.1%
- Veröffentlicht 11.08.2023 14:15:13
- Zuletzt bearbeitet 21.11.2024 08:16:05
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, even after the fix at commit 3492270, malformed `PID_PROPERTY_LIST` parameters cau...
CVE-2023-39948
- EPSS 0.12%
- Veröffentlicht 11.08.2023 14:15:13
- Zuletzt bearbeitet 13.02.2025 17:16:54
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the `BadParamException` thrown by Fast CDR is not caught in Fast DDS. This can remotely crash any ...
CVE-2023-39949
- EPSS 0.11%
- Veröffentlicht 11.08.2023 14:15:13
- Zuletzt bearbeitet 21.11.2024 08:16:05
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can ...
CVE-2023-39417
- EPSS 0.66%
- Veröffentlicht 11.08.2023 13:15:09
- Zuletzt bearbeitet 21.11.2024 08:15:22
IN THE EXTENSION SCRIPT, a SQL Injection vulnerability was found in PostgreSQL if it uses @extowner@, @extschema@, or @extschema:...@ inside a quoting construct (dollar quoting, '', or ""). If an administrator has installed files of a vulnerable, tru...
CVE-2023-39418
- EPSS 0.44%
- Veröffentlicht 11.08.2023 13:15:09
- Zuletzt bearbeitet 06.12.2024 11:15:06
A vulnerability was found in PostgreSQL with the use of the MERGE command, which fails to test new rows against row security policies defined for UPDATE and SELECT. If UPDATE and SELECT policies forbid some rows that INSERT policies do not forbid, a ...
CVE-2023-3824
- EPSS 29.39%
- Veröffentlicht 11.08.2023 06:15:10
- Zuletzt bearbeitet 13.02.2025 17:16:59
In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption...
CVE-2023-3823
- EPSS 0.6%
- Veröffentlicht 11.08.2023 06:15:09
- Zuletzt bearbeitet 13.02.2025 17:16:59
In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state is assumed to be unchanged unle...
CVE-2023-23908
- EPSS 0.01%
- Veröffentlicht 11.08.2023 03:15:18
- Zuletzt bearbeitet 21.11.2024 07:47:04
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.