CVE-2023-27320
- EPSS 0.17%
- Veröffentlicht 28.02.2023 18:15:10
- Zuletzt bearbeitet 21.03.2025 21:15:34
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
CVE-2023-1055
- EPSS 0.05%
- Veröffentlicht 27.02.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:38:22
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the co...
CVE-2023-23916
- EPSS 0.06%
- Veröffentlicht 23.02.2023 20:15:13
- Zuletzt bearbeitet 12.03.2025 19:15:36
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms...
CVE-2023-26081
- EPSS 0.15%
- Veröffentlicht 20.02.2023 03:15:10
- Zuletzt bearbeitet 18.03.2025 15:15:45
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
CVE-2023-24329
- EPSS 1.22%
- Veröffentlicht 17.02.2023 15:15:12
- Zuletzt bearbeitet 18.03.2025 17:15:41
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
CVE-2023-0361
- EPSS 1.2%
- Veröffentlicht 15.02.2023 18:15:11
- Zuletzt bearbeitet 19.03.2025 18:15:18
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a s...
CVE-2023-0003
- EPSS 0.79%
- Veröffentlicht 08.02.2023 18:15:11
- Zuletzt bearbeitet 13.02.2025 17:15:52
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
CVE-2022-46663
- EPSS 0.1%
- Veröffentlicht 07.02.2023 21:15:09
- Zuletzt bearbeitet 25.03.2025 15:15:16
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
CVE-2023-25193
- EPSS 0.05%
- Veröffentlicht 04.02.2023 20:15:08
- Zuletzt bearbeitet 25.03.2025 21:15:41
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
CVE-2023-25136
- EPSS 90.54%
- Veröffentlicht 03.02.2023 06:15:09
- Zuletzt bearbeitet 21.11.2024 07:49:10
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to an...