CVE-2023-28879
- EPSS 31.22%
- Veröffentlicht 31.03.2023 17:15:06
- Zuletzt bearbeitet 14.02.2025 20:15:33
In Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in base/sbcp.c. This affects BCPEncode, BCPDecode, TBCPEncode, and TBCPDecode. If the write buffer is f...
CVE-2023-28755
- EPSS 0.32%
- Veröffentlicht 31.03.2023 04:15:09
- Zuletzt bearbeitet 04.11.2025 18:15:40
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versio...
CVE-2023-28756
- EPSS 0.83%
- Veröffentlicht 31.03.2023 04:15:09
- Zuletzt bearbeitet 04.11.2025 17:15:36
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed vers...
CVE-2023-27535
- EPSS 0.07%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 09.06.2025 15:15:28
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if...
CVE-2023-27536
- EPSS 0.01%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 14.02.2025 16:15:33
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION opt...
CVE-2023-27538
- EPSS 0.02%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 09.06.2025 15:15:29
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previous...
CVE-2022-23121
- EPSS 18.58%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parse_entries function. The issue results fr...
CVE-2022-23122
- EPSS 7.73%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the setfilparams function. The issue results fro...
CVE-2022-23123
- EPSS 7.82%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the getdirparams method. The issue resul...
CVE-2022-23124
- EPSS 0.96%
- Veröffentlicht 28.03.2023 19:15:10
- Zuletzt bearbeitet 04.11.2025 20:16:03
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Netatalk. Authentication is not required to exploit this vulnerability. The specific flaw exists within the get_finderinfo method. The issue res...