CVE-2023-21400
- EPSS 0.04%
- Veröffentlicht 13.07.2023 00:15:24
- Zuletzt bearbeitet 13.02.2025 17:16:02
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exp...
CVE-2023-3618
- EPSS 0.27%
- Veröffentlicht 12.07.2023 15:15:09
- Zuletzt bearbeitet 03.11.2025 21:15:59
A flaw was found in libtiff. A specially crafted tiff file can lead to a segmentation fault due to a buffer overflow in the Fax3Encode function in libtiff/tif_fax3.c, resulting in a denial of service.
CVE-2023-36823
- EPSS 0.42%
- Veröffentlicht 06.07.2023 16:15:10
- Zuletzt bearbeitet 21.11.2024 08:10:40
Sanitize is an allowlist-based HTML and CSS sanitizer. Using carefully crafted input, an attacker may be able to sneak arbitrary HTML and CSS through Sanitize starting with version 3.0.0 and prior to version 6.0.2 when Sanitize is configured to use t...
- EPSS 0.04%
- Veröffentlicht 05.07.2023 21:15:09
- Zuletzt bearbeitet 13.02.2025 17:16:40
Pandoc is a Haskell library for converting from one markup format to another, and a command-line tool that uses this library. Starting in version 1.13 and prior to version 3.1.4, Pandoc is susceptible to an arbitrary file write vulnerability, which c...
CVE-2023-35001
- EPSS 0.22%
- Veröffentlicht 05.07.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 08:07:48
Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace
CVE-2023-31248
- EPSS 0.22%
- Veröffentlicht 05.07.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:01:42
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace
CVE-2023-37211
- EPSS 0.5%
- Veröffentlicht 05.07.2023 10:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:12
Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This ...
CVE-2023-37208
- EPSS 0.05%
- Veröffentlicht 05.07.2023 09:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:12
When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
CVE-2023-37201
- EPSS 0.76%
- Veröffentlicht 05.07.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:10
An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
CVE-2023-37202
- EPSS 0.65%
- Veröffentlicht 05.07.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:11
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird...