CVE-2023-28755
- EPSS 0.34%
- Veröffentlicht 31.03.2023 04:15:09
- Zuletzt bearbeitet 04.11.2025 18:15:40
A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versio...
CVE-2023-28756
- EPSS 0.85%
- Veröffentlicht 31.03.2023 04:15:09
- Zuletzt bearbeitet 04.11.2025 17:15:36
A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed vers...
CVE-2023-1393
- EPSS 0.06%
- Veröffentlicht 30.03.2023 21:15:06
- Zuletzt bearbeitet 29.08.2025 13:42:30
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompSc...
CVE-2023-27533
- EPSS 0.11%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 13.02.2026 21:16:11
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing a...
CVE-2023-27534
- EPSS 0.1%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 23.04.2025 17:16:28
A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its intended use as the first element to indicate a path re...
CVE-2023-27535
- EPSS 0.06%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 09.06.2025 15:15:28
An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if...
CVE-2023-27536
- EPSS 0.01%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 14.02.2025 16:15:33
An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION opt...
CVE-2023-27538
- EPSS 0.01%
- Veröffentlicht 30.03.2023 20:15:07
- Zuletzt bearbeitet 09.06.2025 15:15:29
An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have prevented reuse. libcurl maintains a pool of previous...
CVE-2023-26116
- EPSS 0.25%
- Veröffentlicht 30.03.2023 05:15:07
- Zuletzt bearbeitet 20.11.2025 17:53:57
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a larg...
CVE-2023-26117
- EPSS 0.25%
- Veröffentlicht 30.03.2023 05:15:07
- Zuletzt bearbeitet 20.11.2025 17:53:57
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-cra...