CVE-2023-6918
- EPSS 0.36%
- Veröffentlicht 19.12.2023 00:15:08
- Zuletzt bearbeitet 15.02.2025 01:15:09
A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, ...
CVE-2023-48795
- EPSS 64.06%
- Veröffentlicht 18.12.2023 16:15:10
- Zuletzt bearbeitet 29.09.2025 21:56:10
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client a...
CVE-2023-47038
- EPSS 0.09%
- Veröffentlicht 18.12.2023 14:15:08
- Zuletzt bearbeitet 07.10.2025 18:15:32
A vulnerability was found in perl 5.30.0 through 5.38.0. This issue occurs when a crafted regular expression is compiled by perl, which can allow an attacker controlled byte buffer overflow in a heap allocated buffer.
CVE-2023-6702
- EPSS 35.23%
- Veröffentlicht 14.12.2023 22:15:44
- Zuletzt bearbeitet 21.11.2024 08:44:23
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-5764
- EPSS 0.07%
- Veröffentlicht 12.12.2023 22:15:22
- Zuletzt bearbeitet 21.11.2024 08:42:26
A template injection flaw was found in Ansible where a user's controller internal templating operations may remove the unsafe designation from template data. This issue could allow an attacker to use a specially crafted file to introduce templating i...
CVE-2023-46219
- EPSS 0.19%
- Veröffentlicht 12.12.2023 02:15:06
- Zuletzt bearbeitet 13.02.2025 18:15:34
When saving HSTS data to an excessively long file name, curl could end up removing all contents, making subsequent requests using that file unaware of the HSTS status they should otherwise use.
CVE-2023-6679
- EPSS 0.01%
- Veröffentlicht 11.12.2023 19:15:09
- Zuletzt bearbeitet 21.11.2024 08:44:19
A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service.
CVE-2023-6185
- EPSS 1.22%
- Veröffentlicht 11.12.2023 12:15:07
- Zuletzt bearbeitet 13.02.2025 18:16:06
Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped wh...
CVE-2023-6186
- EPSS 1.09%
- Veröffentlicht 11.12.2023 12:15:07
- Zuletzt bearbeitet 13.02.2025 18:16:06
Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning. In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that c...
CVE-2023-6622
- EPSS 0.01%
- Veröffentlicht 08.12.2023 18:15:07
- Zuletzt bearbeitet 25.06.2025 20:52:54
A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of service.