CVE-2023-35001
- EPSS 0.21%
- Published 05.07.2023 19:15:10
- Last modified 21.11.2024 08:07:48
Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace
CVE-2023-31248
- EPSS 0.2%
- Published 05.07.2023 19:15:09
- Last modified 21.11.2024 08:01:42
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace
CVE-2023-36053
- EPSS 4.8%
- Published 03.07.2023 13:15:09
- Last modified 21.11.2024 08:09:14
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
CVE-2023-30589
- EPSS 1.92%
- Published 01.07.2023 00:15:10
- Last modified 13.02.2025 17:16:25
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the ...
CVE-2023-1206
- EPSS 0.02%
- Published 30.06.2023 22:15:09
- Last modified 21.11.2024 07:38:40
A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth connection can increase the CP...
CVE-2023-3431
- EPSS 0.17%
- Published 27.06.2023 15:15:11
- Last modified 21.11.2024 08:17:15
Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9.
- EPSS 0.18%
- Published 27.06.2023 15:15:11
- Last modified 21.11.2024 08:17:15
Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
CVE-2023-36664
- EPSS 4.52%
- Published 25.06.2023 22:15:21
- Last modified 05.12.2024 15:15:07
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
CVE-2023-3212
- EPSS 0.01%
- Published 23.06.2023 20:15:09
- Last modified 21.11.2024 08:16:42
A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileg...
CVE-2023-34241
- EPSS 0.05%
- Published 22.06.2023 23:15:09
- Last modified 21.11.2024 08:06:50
OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has b...