CVE-2023-32762
- EPSS 0.12%
- Veröffentlicht 28.05.2023 23:15:09
- Zuletzt bearbeitet 21.11.2024 08:03:59
An issue was discovered in Qt before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. Qt Network incorrectly parses the strict-transport-security (HSTS) header, allowing unencrypted connections to be established, even when explicitly ...
CVE-2023-32307
- EPSS 0.36%
- Veröffentlicht 26.05.2023 23:15:10
- Zuletzt bearbeitet 14.01.2025 20:15:26
Sofia-SIP is an open-source SIP User-Agent library, compliant with the IETF RFC3261 specification. Referring to [GHSA-8599-x7rq-fr54](https://github.com/freeswitch/sofia-sip/security/advisories/GHSA-8599-x7rq-fr54), several other potential heap-over-...
CVE-2023-2898
- EPSS 0.02%
- Veröffentlicht 26.05.2023 22:15:14
- Zuletzt bearbeitet 21.11.2024 07:59:31
There is a null-pointer-dereference flaw found in f2fs_write_end_io in fs/f2fs/data.c in the Linux kernel. This flaw allows a local privileged user to cause a denial of service problem.
CVE-2023-2879
- EPSS 0.11%
- Veröffentlicht 26.05.2023 21:15:19
- Zuletzt bearbeitet 03.11.2025 22:16:08
GDSDB infinite loop in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via packet injection or crafted capture file
CVE-2023-2857
- EPSS 0.05%
- Veröffentlicht 26.05.2023 21:15:18
- Zuletzt bearbeitet 15.01.2025 16:15:27
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVE-2023-2858
- EPSS 0.06%
- Veröffentlicht 26.05.2023 21:15:18
- Zuletzt bearbeitet 03.11.2025 22:16:08
NetScaler file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVE-2023-2854
- EPSS 0.05%
- Veröffentlicht 26.05.2023 21:15:17
- Zuletzt bearbeitet 15.01.2025 16:15:27
BLF file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVE-2023-2855
- EPSS 0.06%
- Veröffentlicht 26.05.2023 21:15:17
- Zuletzt bearbeitet 03.11.2025 22:16:07
Candump log parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVE-2023-2856
- EPSS 0.04%
- Veröffentlicht 26.05.2023 21:15:17
- Zuletzt bearbeitet 03.11.2025 22:16:07
VMS TCPIPtrace file parser crash in Wireshark 4.0.0 to 4.0.5 and 3.6.0 to 3.6.13 allows denial of service via crafted capture file
CVE-2023-28321
- EPSS 0.27%
- Veröffentlicht 26.05.2023 21:15:16
- Zuletzt bearbeitet 15.01.2025 16:15:26
An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function...