Search

Found 5,520 results in 760ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-3978 medium 5.5 FIX rocky rhel sles 3y ago Text nodes not in the HTML namespace are incorrectly literally rendered, causing text which should be escaped to not be. This could lead to an XSS attack.
CVE-2023-3961 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7467: samba security update (Moderate)
CVE-2023-39322 medium 5.5 FIX rhel rocky sles 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-39321 medium 5.5 FIX rhel rocky sles 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-39319 medium 5.5 FIX rhel rocky sles 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-39318 medium 5.5 FIX rhel rocky sles 3y ago Moderate: container-tools:rhel8 security update
CVE-2023-38712 medium 5.5 FIX rheldebian debian 3y ago RHSA-2023:7052: libreswan security update (Moderate)
CVE-2023-38711 medium 5.5 FIX rheldebian debian 3y ago RHSA-2023:7052: libreswan security update (Moderate)
CVE-2023-38710 medium 5.5 FIX rheldebian debian 3y ago RHSA-2023:7052: libreswan security update (Moderate)
CVE-2023-38559 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7053: ghostscript security and bug fix update (Moderate)
CVE-2023-38197 medium 5.5 FIX rhel slesdebian debian 3y ago An issue was discovered in Qt before 5.15.15, 6.x before 6.2.10, and 6.3.x through 6.5.x before 6.5.3. There are infinite loops in recursive entity expansion.
CVE-2023-3750 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libvirt security, bug fix, and enhancement update
CVE-2023-37369 medium 5.5 FIX rhel slesdebian debian 3y ago In Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2, there can be an application crash in QXmlStreamReader via a crafted XML string that triggers a situation in which a prefi…
CVE-2023-36054 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: krb5 security and bug fix update
CVE-2023-35789 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7150: librabbitmq security update (Moderate)
CVE-2023-3576 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libtiff security update
CVE-2023-34968 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7139: samba security, bug fix, and enhancement update (Moderate)
CVE-2023-34967 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7139: samba security, bug fix, and enhancement update (Moderate)
CVE-2023-34966 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7139: samba security, bug fix, and enhancement update (Moderate)
CVE-2023-34410 medium 5.5 FIX rhel slesdebian debian 3y ago An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configur…
CVE-2023-34241 medium 5.5 FIX rheldebian debian sles 3y ago RHSA-2023:7165: cups security and bug fix update (Moderate)
CVE-2023-33460 medium 5.5 FIX rhel rockydebian debian 3y ago RHSA-2023:7057: yajl security update (Moderate)
CVE-2023-33285 medium 5.5 FIX rhel slesdebian debian 3y ago An issue was discovered in Qt 5.x before 5.15.14, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1. QDnsLookup has a buffer over-read via a crafted reply from a DNS server.
CVE-2023-33204 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7010: sysstat security and bug fix update (Moderate)
CVE-2023-3316 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libtiff security update
CVE-2023-32665 low 2.5 FIX rhel slesdebian debian 3y ago Low: glib2 security and bug fix update
CVE-2023-32611 low 2.5 FIX rhel slesdebian debian 3y ago Low: glib2 security and bug fix update
CVE-2023-32573 low 2.5 FIX rhel slesdebian debian 3y ago In Qt before 5.15.14, 6.0.x through 6.2.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.1, QtSvg QSvgFont m_unitsPerEm initialization is mishandled.
CVE-2023-32324 medium 5.5 FIX rheldebian debian sles 3y ago RHSA-2023:7165: cups security and bug fix update (Moderate)
CVE-2023-31486 medium 5.5 FIX rhel rocky sles 3y ago HTTP::Tiny before 0.083, a Perl core module since 5.13.9 and available standalone on CPAN, has an insecure default TLS configuration where users must opt in to verify certificates.
CVE-2023-31484 medium 5.5 FIX rhel rocky sles 3y ago CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
CVE-2023-3138 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7029: libX11 security update (Moderate)
CVE-2023-2977 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7160: opensc security and bug fix update (Low)
CVE-2023-2952 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7015: wireshark security update (Moderate)
CVE-2023-29499 low 2.5 FIX rhel slesdebian debian 3y ago Low: glib2 security and bug fix update
CVE-2023-29491 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:5249: ncurses security update (Moderate)
CVE-2023-28879 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7053: ghostscript security and bug fix update (Moderate)
CVE-2023-28709 medium 5.5 FIX rhel slesdebian debian 3y ago The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used suc…
CVE-2023-28708 medium 5.5 FIX rhel slesdebian debian 3y ago When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to …
CVE-2023-28642 medium 5.5 FIX rocky rhel sles 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-28625 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:6940: mod_auth_openidc:2.3 security and bug fix update (Moderate)
CVE-2023-2858 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7015: wireshark security update (Moderate)
CVE-2023-2856 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7015: wireshark security update (Moderate)
CVE-2023-2855 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: wireshark security update
CVE-2023-28450 medium 5.5 FIX rheldebian debian sles 3y ago RHSA-2023:7046: dnsmasq security and bug fix update (Moderate)
CVE-2023-28370 medium 5.5 FIX rhel slesdebian debian 3y ago Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user acc…
CVE-2023-28101 medium 5.5 FIX rheldebian debian sles 3y ago RHSA-2023:7038: flatpak security, bug fix, and enhancement update (Moderate)
CVE-2023-28100 medium 5.5 FIX rheldebian debian sles 3y ago RHSA-2023:7038: flatpak security, bug fix, and enhancement update (Moderate)
CVE-2023-27561 medium 5.5 FIX rocky rhel sles 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-27538 medium 5.5 FIX rheldebian debian sles 3y ago An authentication bypass vulnerability exists in libcurl prior to v8.0.0 where it reuses a previously established SSH connection despite the fact that an SSH option was modified, which should have pr…
CVE-2023-27536 medium 5.5 FIX rheldebian debian rocky 3y ago An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to che…
CVE-2023-27534 medium 5.5 FIX rheldebian debian sles 3y ago A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its inte…
CVE-2023-27533 medium 5.5 FIX rheldebian debian sles 3y ago A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during serve…
CVE-2023-27522 medium 5.5 FIX debian debian rhel rocky 3y ago HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header c…
CVE-2023-27371 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7090: libmicrohttpd security update (Moderate)
CVE-2023-2731 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libtiff security update
CVE-2023-26966 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libtiff security update
CVE-2023-26965 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libtiff security update
CVE-2023-2680 medium 5.5 FIX rheldebian debianalmalinux almalinux 3y ago This CVE exists because of an incomplete fix for CVE-2021-3750. More specifically, the qemu-kvm package as released for Red Hat Enterprise Linux 9.1 via RHSA-2022:7967 included a version of qemu-kvm …
CVE-2023-26769 medium 5.5 FIX rhel slesdebian debian 3y ago Buffer Overflow vulnerability found in Liblouis Lou_Trace v.3.24.0 allows a remote attacker to cause a denial of service via the resolveSubtable function at compileTranslationTabel.c.
CVE-2023-26768 medium 5.5 FIX rhel slesdebian debian 3y ago Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the compileTranslationTable.c and lou_setDataPath functions.
CVE-2023-26767 medium 5.5 FIX rhel slesdebian debian 3y ago Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the lou_logFile function at logginc.c endpoint.
CVE-2023-25809 medium 5.5 FIX rocky rhel sles 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-25173 medium 5.5 FIX rocky rheldebian debian 3y ago RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate)
CVE-2023-24998 medium 5.5 FIX rhelarch arch sles 3y ago Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploa…
CVE-2023-23931 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2024:2985: python39:3.9 and python39-devel:3.9 security update (Moderate)
CVE-2023-2283 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2023:3839: libssh security update (Moderate)
CVE-2023-22745 low 2.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7166: tpm2-tss security and enhancement update (Low)
CVE-2023-2255 medium 5.5 FIX rhel slesdebian debian 3y ago Improper access control in editor components of The Document Foundation LibreOffice allowed an attacker to craft a document that would cause external links to be loaded without prompt. In the affecte…
CVE-2023-1981 medium 5.5 FIX debian debian rhel rocky 3y ago Moderate: avahi security update
CVE-2023-1786 medium 5.5 FIX rheldebian debian sles 3y ago RHSA-2023:6943: cloud-init security, bug fix, and enhancement update (Moderate)
CVE-2023-1672 medium 5.5 FIX rheldebian debian 3y ago RHSA-2023:7022: tang security and bug fix update (Moderate)
CVE-2023-1667 medium 5.5 FIX rhel rocky sles 3y ago RHSA-2023:3839: libssh security update (Moderate)
CVE-2023-1183 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: libreoffice security update
CVE-2023-0950 medium 5.5 FIX rhel slesdebian debian 3y ago Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index …
CVE-2023-0836 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: haproxy security and bug fix update
CVE-2023-0668 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: wireshark security update
CVE-2023-0666 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:7015: wireshark security update (Moderate)
CVE-2022-50865 medium 5.5 FIX rocky rhel sles 3y ago In the Linux kernel, the following vulnerability has been resolved: tcp: fix a signed-integer-overflow bug in tcp_add_backlog() The type of sk_rcvbuf and sk_sndbuf in struct sock is int, and in tcp…
CVE-2022-50856 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: cifs: Fix xid leak in cifs_ses_add_channel() Before return, should free the xid, otherwise, the xid will be leaked.
CVE-2022-50543 medium 5.5 FIX rocky rhel sles 3y ago In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix mr->map double free rxe_mr_cleanup() which tries to free mr->map again will be called when rxe_mr_init_user() fails…
CVE-2022-50472 medium 5.5 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: IB/mad: Don't call to function that might sleep while in atomic context Tracepoints are not allowed to sleep, as such the followi…
CVE-2022-50423 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: ACPICA: Fix use-after-free in acpi_ut_copy_ipackage_to_ipackage() There is an use-after-free reported by KASAN: BUG: KASAN: us…
CVE-2022-50369 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix null-ptr-deref in vkms_release() A null-ptr-deref is triggered when it tries to destroy the workqueue in vkms->outp…
CVE-2022-50341 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: cifs: fix oops during encryption When running xfstests against Azure the following oops occurred on an arm64 system Unable to …
CVE-2022-50327 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value The return value of acpi_fetch_acpi_dev() could be NULL, which wo…
CVE-2022-50269 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Fix memory leak in vkms_init() A memory leak was reported after the vkms module install failed. unreferenced object 0x…
CVE-2022-50110 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: watchdog: sp5100_tco: Fix a memory leak of EFCH MMIO resource Unlike release_mem_region(), a call to release_resource() does not …
CVE-2022-50087 medium 5.5 FIX rhel rocky sles 3y ago Moderate: kernel security update
CVE-2022-50042 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: net: genl: fix error path memory leak in policy dumping If construction of the array of policies fails when recording non-first p…
CVE-2022-49885 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: ACPI: APEI: Fix integer overflow in ghes_estatus_pool_init() Change num_ghes from int to unsigned int, preventing an overflow and…
CVE-2022-49759 medium 5.5 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: VMCI: Use threaded irqs instead of tasklets The vmci_dispatch_dgs() tasklet function calls vmci_read_data() which uses wait_event…
CVE-2022-48468 medium 5.5 FIX rhel slesdebian debian 3y ago RHSA-2023:6944: protobuf-c security update (Moderate)
CVE-2022-43681 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: frr security and bug fix update
CVE-2022-4285 medium 5.5 FIX rheldebian debian rocky 3y ago RHSA-2023:6236: binutils security update (Moderate)
CVE-2022-40898 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: python-wheel security update
CVE-2022-40318 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: frr security and bug fix update
CVE-2022-40302 medium 5.5 FIX rhel slesdebian debian 3y ago Moderate: frr security and bug fix update
CVE-2022-39324 medium 5.5 rhel sles 3y ago Moderate: grafana security and enhancement update
CVE-2022-39307 medium 5.5 rhel sles 3y ago Moderate: grafana security and enhancement update