CVE-2023-5217
- EPSS 1.8%
- Veröffentlicht 28.09.2023 16:15:10
- Zuletzt bearbeitet 03.04.2025 18:55:36
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-42756
- EPSS 0.01%
- Veröffentlicht 28.09.2023 14:15:21
- Zuletzt bearbeitet 21.11.2024 08:23:06
A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash...
CVE-2023-42822
- EPSS 0.34%
- Veröffentlicht 27.09.2023 18:15:11
- Zuletzt bearbeitet 10.04.2025 20:44:22
xrdp is an open source remote desktop protocol server. Access to the font glyphs in xrdp_painter.c is not bounds-checked . Since some of this data is controllable by the user, this can result in an out-of-bounds read within the xrdp executable. The v...
CVE-2023-5169
- EPSS 0.32%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 21.11.2024 08:41:13
A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115...
CVE-2023-5171
- EPSS 0.32%
- Veröffentlicht 27.09.2023 15:19:42
- Zuletzt bearbeitet 21.11.2024 08:41:13
During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and...
CVE-2023-5157
- EPSS 0.27%
- Veröffentlicht 27.09.2023 15:19:41
- Zuletzt bearbeitet 01.10.2025 15:15:41
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
CVE-2023-42453
- EPSS 0.17%
- Veröffentlicht 27.09.2023 15:19:32
- Zuletzt bearbeitet 21.11.2024 08:22:33
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not able to view the events, but s...
CVE-2023-41335
- EPSS 0.11%
- Veröffentlicht 27.09.2023 15:19:30
- Zuletzt bearbeitet 21.11.2024 08:21:06
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant the server any added capabili...
CVE-2023-41074
- EPSS 1.12%
- Veröffentlicht 27.09.2023 15:19:26
- Zuletzt bearbeitet 21.11.2024 08:20:30
The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.
CVE-2023-35074
- EPSS 0.6%
- Veröffentlicht 27.09.2023 15:18:52
- Zuletzt bearbeitet 05.05.2025 16:15:40
The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.