CVE-2023-6346
- EPSS 0.45%
- Veröffentlicht 29.11.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:40
Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-6347
- EPSS 0.46%
- Veröffentlicht 29.11.2023 12:15:07
- Zuletzt bearbeitet 05.06.2025 14:15:30
Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-6348
- EPSS 0.87%
- Veröffentlicht 29.11.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:40
Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-6350
- EPSS 1.2%
- Veröffentlicht 29.11.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:40
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
CVE-2023-6351
- EPSS 0.28%
- Veröffentlicht 29.11.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:40
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
CVE-2023-5981
- EPSS 0.56%
- Veröffentlicht 28.11.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 08:42:54
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
CVE-2023-6277
- EPSS 0.42%
- Veröffentlicht 24.11.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:31
An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.
CVE-2023-5972
- EPSS 0.02%
- Veröffentlicht 23.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:42:53
A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.
CVE-2023-6238
- EPSS 0.02%
- Veröffentlicht 21.11.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:43:26
A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unre...
CVE-2023-5341
- EPSS 0.04%
- Veröffentlicht 19.11.2023 10:15:49
- Zuletzt bearbeitet 07.02.2025 03:15:10
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.