CVE-2023-3428
- EPSS 0.02%
- Published 04.10.2023 19:15:10
- Last modified 21.11.2024 08:17:14
A heap-based buffer overflow vulnerability was found in coders/tiff.c in ImageMagick. This issue may allow a local attacker to trick the user into opening a specially crafted file, resulting in an application crash and denial of service.
CVE-2023-3576
- EPSS 0.03%
- Published 04.10.2023 19:15:10
- Last modified 21.11.2024 08:17:35
A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an a...
CVE-2023-43804
- EPSS 0.47%
- Published 04.10.2023 17:15:10
- Last modified 13.12.2024 14:15:20
urllib3 is a user-friendly HTTP client library for Python. urllib3 doesn't treat the `Cookie` HTTP header special or provide any helpers for managing cookies over HTTP, that is the responsibility of the user. However, it is possible for a user to spe...
CVE-2023-4911
- EPSS 78.36%
- Published 03.10.2023 18:15:10
- Last modified 06.05.2025 21:02:34
A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES environment variables when launch...
CVE-2023-5345
- EPSS 0.02%
- Published 03.10.2023 03:15:09
- Last modified 20.03.2025 16:59:45
A use-after-free vulnerability in the Linux kernel's fs/smb/client component can be exploited to achieve local privilege escalation. In case of an error in smb3_fs_context_parse_param, ctx->password was freed but the field was not set to NULL which ...
CVE-2023-5344
- EPSS 0.06%
- Published 02.10.2023 20:15:10
- Last modified 21.11.2024 08:41:34
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.1969.
CVE-2023-44488
- EPSS 0.82%
- Published 30.09.2023 20:15:10
- Last modified 21.11.2024 08:25:59
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
CVE-2023-43655
- EPSS 2.26%
- Published 29.09.2023 20:15:09
- Last modified 23.04.2025 17:31:40
Composer is a dependency manager for PHP. Users publishing a composer.phar to a public web-accessible server where the composer.phar can be executed as a php file may be subject to a remote code execution vulnerability if PHP also has `register_argc_...
CVE-2023-5186
- EPSS 1.54%
- Published 28.09.2023 16:15:10
- Last modified 21.11.2024 08:41:15
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: H...
CVE-2023-5187
- EPSS 0.28%
- Published 28.09.2023 16:15:10
- Last modified 21.11.2024 08:41:15
Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)