CVE-2023-5539
- EPSS 1.83%
- Veröffentlicht 09.11.2023 20:15:08
- Zuletzt bearbeitet 21.11.2024 08:41:58
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
CVE-2023-5996
- EPSS 0.57%
- Veröffentlicht 08.11.2023 20:15:07
- Zuletzt bearbeitet 21.11.2024 08:42:56
Use after free in WebAudio in Google Chrome prior to 119.0.6045.123 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-4535
- EPSS 0.26%
- Veröffentlicht 06.11.2023 17:15:12
- Zuletzt bearbeitet 21.11.2024 08:35:21
An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or s...
CVE-2023-47272
- EPSS 0.65%
- Veröffentlicht 06.11.2023 00:15:09
- Zuletzt bearbeitet 21.11.2024 08:30:05
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
CVE-2023-3961
- EPSS 1.94%
- Veröffentlicht 03.11.2023 13:15:08
- Zuletzt bearbeitet 21.11.2024 08:18:24
A path traversal vulnerability was identified in Samba when processing client pipe names connecting to Unix domain sockets within a private directory. Samba typically uses this mechanism to connect SMB clients to remote procedure call (RPC) services ...
CVE-2023-4091
- EPSS 0.48%
- Veröffentlicht 03.11.2023 08:15:08
- Zuletzt bearbeitet 21.11.2024 08:34:22
A vulnerability was discovered in Samba, where the flaw allows SMB clients to truncate files, even with read-only permissions when the Samba VFS module "acl_xattr" is configured with "acl_xattr:ignore system acls = yes". The SMB protocol allows openi...
CVE-2023-1194
- EPSS 0.09%
- Veröffentlicht 03.11.2023 08:15:07
- Zuletzt bearbeitet 20.03.2025 17:01:03
An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missi...
CVE-2023-42670
- EPSS 0.64%
- Veröffentlicht 03.11.2023 08:15:07
- Zuletzt bearbeitet 21.11.2024 08:22:55
A flaw was found in Samba. It is susceptible to a vulnerability where multiple incompatible RPC listeners can be initiated, causing disruptions in the AD DC service. When Samba's RPC server experiences a high load or unresponsiveness, servers intende...
- EPSS 0.06%
- Veröffentlicht 03.11.2023 05:15:30
- Zuletzt bearbeitet 21.11.2024 08:21:54
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.
CVE-2023-43665
- EPSS 2.79%
- Veröffentlicht 03.11.2023 05:15:30
- Zuletzt bearbeitet 04.11.2025 18:15:41
In Django 3.2 before 3.2.22, 4.1 before 4.1.12, and 4.2 before 4.2.6, the django.utils.text.Truncator chars() and words() methods (when used with html=True) are subject to a potential DoS (denial of service) attack via certain inputs with very long, ...