CVE-2023-45866
- EPSS 28.27%
- Veröffentlicht 08.12.2023 06:15:45
- Zuletzt bearbeitet 12.12.2024 14:33:00
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has oc...
CVE-2023-46218
- EPSS 0.43%
- Veröffentlicht 07.12.2023 01:15:07
- Zuletzt bearbeitet 30.06.2025 17:15:29
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites ...
CVE-2023-6508
- EPSS 0.91%
- Veröffentlicht 06.12.2023 02:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:59
Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-6509
- EPSS 1.17%
- Veröffentlicht 06.12.2023 02:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:59
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security sev...
CVE-2023-6510
- EPSS 1.24%
- Veröffentlicht 06.12.2023 02:15:07
- Zuletzt bearbeitet 21.11.2024 08:44:00
Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severit...
CVE-2023-6511
- EPSS 0.2%
- Veröffentlicht 06.12.2023 02:15:07
- Zuletzt bearbeitet 21.11.2024 08:44:00
Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-6512
- EPSS 0.6%
- Veröffentlicht 06.12.2023 02:15:07
- Zuletzt bearbeitet 28.05.2025 16:15:32
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)
CVE-2023-42916
- EPSS 0.04%
- Veröffentlicht 30.11.2023 23:15:07
- Zuletzt bearbeitet 29.11.2024 15:03:51
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that th...
CVE-2023-42917
- EPSS 0.06%
- Veröffentlicht 30.11.2023 23:15:07
- Zuletzt bearbeitet 10.02.2025 17:55:21
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report th...
CVE-2023-6345
- EPSS 0.26%
- Veröffentlicht 29.11.2023 12:15:07
- Zuletzt bearbeitet 10.03.2025 20:33:27
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)