CVE-2023-6112
- EPSS 20.89%
- Veröffentlicht 15.11.2023 18:15:06
- Zuletzt bearbeitet 21.11.2024 08:43:09
Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-23583
- EPSS 0.04%
- Veröffentlicht 14.11.2023 19:15:18
- Zuletzt bearbeitet 07.01.2025 22:15:28
Sequence of processor instructions leads to unexpected behavior for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege and/or information disclosure and/or denial of service via local access.
CVE-2023-46849
- EPSS 0.31%
- Veröffentlicht 11.11.2023 01:15:07
- Zuletzt bearbeitet 11.06.2025 15:15:26
Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.
CVE-2023-46850
- EPSS 2.16%
- Veröffentlicht 11.11.2023 01:15:07
- Zuletzt bearbeitet 21.11.2024 08:29:25
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
CVE-2023-5996
- EPSS 0.74%
- Veröffentlicht 08.11.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 08:42:56
Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-47272
- EPSS 0.65%
- Veröffentlicht 06.11.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:30:05
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
CVE-2023-5849
- EPSS 1.14%
- Veröffentlicht 01.11.2023 18:15:10
- Zuletzt bearbeitet 29.04.2025 21:15:50
Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-5850
- EPSS 0.86%
- Veröffentlicht 01.11.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 08:42:37
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
CVE-2023-5851
- EPSS 0.46%
- Veröffentlicht 01.11.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 08:42:37
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
CVE-2023-5852
- EPSS 0.66%
- Veröffentlicht 01.11.2023 18:15:10
- Zuletzt bearbeitet 29.04.2025 21:15:50
Use after free in Printing in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)