CVE-2023-6348
- EPSS 1.08%
- Veröffentlicht 29.11.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:40
Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-6350
- EPSS 1.3%
- Veröffentlicht 29.11.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:40
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
CVE-2023-6351
- EPSS 0.93%
- Veröffentlicht 29.11.2023 12:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:40
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
CVE-2023-5981
- EPSS 1.27%
- Veröffentlicht 28.11.2023 12:15:07
- Zuletzt bearbeitet 25.03.2026 20:01:09
A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
CVE-2023-6277
- EPSS 1.81%
- Veröffentlicht 24.11.2023 19:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:31
An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.
CVE-2023-5972
- EPSS 0.28%
- Veröffentlicht 23.11.2023 18:15:07
- Zuletzt bearbeitet 21.11.2024 08:42:53
A null pointer dereference flaw was found in the nft_inner.c functionality of netfilter in the Linux kernel. This issue could allow a local user to crash the system or escalate their privileges on the system.
CVE-2023-48706
- EPSS 0.45%
- Veröffentlicht 22.11.2023 22:15:08
- Zuletzt bearbeitet 17.09.2026 17:59:18
Vim is a UNIX editor that, prior to version 9.0.2121, has a heap-use-after-free vulnerability. When executing a `:s` command for the very first time and using a sub-replace-special atom inside the substitution part, it is possible that the recursive ...
CVE-2023-6238
- EPSS 0.29%
- Veröffentlicht 21.11.2023 21:15:09
- Zuletzt bearbeitet 21.11.2024 08:43:26
A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unre...
CVE-2023-5341
- EPSS 0.44%
- Veröffentlicht 19.11.2023 10:15:49
- Zuletzt bearbeitet 07.02.2025 03:15:10
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
CVE-2023-48234
- EPSS 0.76%
- Veröffentlicht 16.11.2023 23:15:09
- Zuletzt bearbeitet 23.06.2026 18:17:34
Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for large counts given. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has ...