CVE-2023-30943
- EPSS 18.45%
- Published 02.05.2023 20:15:10
- Last modified 21.11.2024 08:01:07
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
CVE-2023-1786
- EPSS 0.02%
- Published 26.04.2023 23:15:08
- Last modified 21.11.2024 07:39:54
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
CVE-2023-29007
- EPSS 1.42%
- Published 25.04.2023 21:15:10
- Last modified 21.11.2024 07:56:22
Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially crafted `.gitmodules` file with submodule URLs that are longer than 1024 characters can used t...
CVE-2023-2269
- EPSS 0.03%
- Published 25.04.2023 21:15:10
- Last modified 21.11.2024 07:58:16
A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component.
CVE-2023-25652
- EPSS 3.18%
- Published 25.04.2023 20:15:09
- Last modified 21.11.2024 07:49:52
Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, by feeding specially crafted input to `git apply --reject`, a path outside the working tree can be overwri...
CVE-2023-25815
- EPSS 0.09%
- Published 25.04.2023 20:15:09
- Last modified 21.11.2024 07:50:15
In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-packages, th...
CVE-2022-42335
- EPSS 0.06%
- Published 25.04.2023 13:15:09
- Last modified 21.11.2024 07:24:46
x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in one of the...
CVE-2023-29530
- EPSS 0.18%
- Published 24.04.2023 20:15:08
- Last modified 21.11.2024 07:57:14
Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0, users who create HTTP requests or responses using laminas/laminas-diactoros, when providing a newli...
CVE-2023-31084
- EPSS 0.01%
- Published 24.04.2023 06:15:07
- Last modified 18.03.2025 20:15:19
An issue was discovered in drivers/media/dvb-core/dvb_frontend.c in the Linux kernel 6.2. There is a blocking operation when a task is in !TASK_RUNNING. In dvb_frontend_get_event, wait_event_interruptible is called; the condition is dvb_frontend_test...
CVE-2023-2194
- EPSS 0.02%
- Published 20.04.2023 21:15:09
- Last modified 23.04.2025 17:16:29
An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of ...