CVE-2023-27320
- EPSS 0.17%
- Published 28.02.2023 18:15:10
- Last modified 21.03.2025 21:15:34
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
CVE-2023-1055
- EPSS 0.05%
- Published 27.02.2023 22:15:09
- Last modified 21.11.2024 07:38:22
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the co...
CVE-2023-23916
- EPSS 0.06%
- Published 23.02.2023 20:15:13
- Last modified 12.03.2025 19:15:36
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms...
CVE-2023-26081
- EPSS 0.15%
- Published 20.02.2023 03:15:10
- Last modified 18.03.2025 15:15:45
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
CVE-2023-24329
- EPSS 1.22%
- Published 17.02.2023 15:15:12
- Last modified 18.03.2025 17:15:41
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
CVE-2023-0361
- EPSS 1.2%
- Published 15.02.2023 18:15:11
- Last modified 19.03.2025 18:15:18
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a s...
CVE-2023-0003
- EPSS 0.79%
- Published 08.02.2023 18:15:11
- Last modified 13.02.2025 17:15:52
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
CVE-2022-46663
- EPSS 0.1%
- Published 07.02.2023 21:15:09
- Last modified 25.03.2025 15:15:16
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
CVE-2023-25193
- EPSS 0.05%
- Published 04.02.2023 20:15:08
- Last modified 25.03.2025 21:15:41
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
CVE-2023-25136
- EPSS 90.54%
- Published 03.02.2023 06:15:09
- Last modified 21.11.2024 07:49:10
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to an...