CVE-2023-29197
- EPSS 2.29%
- Veröffentlicht 17.04.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:56:41
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Affected versions are subject to improper header parsing. An attacker could sneak in a newline (\n) into both the header names and values. While the specification states that \r\n...
CVE-2021-43612
- EPSS 0.12%
- Veröffentlicht 15.04.2023 22:15:07
- Zuletzt bearbeitet 06.02.2025 16:15:30
In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
CVE-2023-2033
- EPSS 13.9%
- Veröffentlicht 14.04.2023 19:15:09
- Zuletzt bearbeitet 19.02.2025 19:44:57
Type confusion in V8 in Google Chrome prior to 112.0.5615.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-1994
- EPSS 0.2%
- Veröffentlicht 12.04.2023 22:15:13
- Zuletzt bearbeitet 07.02.2025 17:15:23
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
CVE-2023-1906
- EPSS 0.03%
- Veröffentlicht 12.04.2023 22:15:11
- Zuletzt bearbeitet 10.02.2025 17:15:15
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an app...
CVE-2023-1993
- EPSS 0.07%
- Veröffentlicht 12.04.2023 21:15:16
- Zuletzt bearbeitet 07.02.2025 17:15:23
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
CVE-2023-1992
- EPSS 0.21%
- Veröffentlicht 12.04.2023 21:15:15
- Zuletzt bearbeitet 07.02.2025 17:15:23
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
CVE-2023-0004
- EPSS 0.72%
- Veröffentlicht 12.04.2023 17:15:07
- Zuletzt bearbeitet 21.11.2024 07:36:22
A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the ...
CVE-2023-1810
- EPSS 0.94%
- Veröffentlicht 04.04.2023 22:15:07
- Zuletzt bearbeitet 21.11.2024 07:39:56
Heap buffer overflow in Visuals in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2023-1811
- EPSS 0.66%
- Veröffentlicht 04.04.2023 22:15:07
- Zuletzt bearbeitet 21.11.2024 07:39:56
Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)