CVE-2022-4645
- EPSS 0.01%
- Veröffentlicht 03.03.2023 16:15:09
- Zuletzt bearbeitet 04.04.2025 21:15:42
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
CVE-2023-25358
- EPSS 0.14%
- Veröffentlicht 02.03.2023 15:15:10
- Zuletzt bearbeitet 07.03.2025 16:15:37
A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVE-2023-1127
- EPSS 0.04%
- Veröffentlicht 01.03.2023 19:15:25
- Zuletzt bearbeitet 21.11.2024 07:38:30
Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.
CVE-2022-41727
- EPSS 0.03%
- Veröffentlicht 28.02.2023 18:15:10
- Zuletzt bearbeitet 21.11.2024 07:23:44
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
CVE-2023-27320
- EPSS 0.18%
- Veröffentlicht 28.02.2023 18:15:10
- Zuletzt bearbeitet 21.03.2025 21:15:34
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
CVE-2023-1055
- EPSS 0.06%
- Veröffentlicht 27.02.2023 22:15:09
- Zuletzt bearbeitet 21.11.2024 07:38:22
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the co...
CVE-2023-23916
- EPSS 0.06%
- Veröffentlicht 23.02.2023 20:15:13
- Zuletzt bearbeitet 12.03.2025 19:15:36
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms...
CVE-2023-26081
- EPSS 0.15%
- Veröffentlicht 20.02.2023 03:15:10
- Zuletzt bearbeitet 18.03.2025 15:15:45
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
CVE-2023-24329
- EPSS 1.44%
- Veröffentlicht 17.02.2023 15:15:12
- Zuletzt bearbeitet 03.11.2025 22:16:05
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
CVE-2023-0361
- EPSS 3.13%
- Veröffentlicht 15.02.2023 18:15:11
- Zuletzt bearbeitet 19.03.2025 18:15:18
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a s...