Search

Found 4,677 results in 665ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2024-23222 high 9.5 KEVFIX rhel slesdebian debian 3y ago A type confusion issue was addressed with improved checks. This issue is fixed in Safari 17.3, iOS 15.8.7 and iPadOS 15.8.7, iOS 16.7.5 and iPadOS 16.7.5, iOS 17.3 and iPadOS 17.3, macOS Monterey 12.…
CVE-2023-42916 high 9.5 KEVFIX rhel slesdebian debian 3y ago An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensit…
CVE-2023-41993 high 9.5 KEVFIX rhel slesdebian debian 3y ago The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have …
CVE-2023-41074 high 8.0 FIX rhel slesdebian debian 3y ago The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution.
CVE-2023-38595 high 8.0 FIX rheldebian debianalmalinux almalinux 3y ago The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web content may lead to arbitrary co…
CVE-2023-38594 high 8.0 FIX rhel slesdebian debian 3y ago The issue was addressed with improved checks. This issue is fixed in iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Ventura 13.5, Safari 16.6, watchOS 9.6. Processing web co…
CVE-2023-37450 high 9.5 KEVFIX rhel rocky sles 3y ago The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary …
CVE-2023-35074 high 8.0 FIX rhel slesdebian debian 3y ago The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code …
CVE-2023-32439 high 9.5 KEVFIX rhel rocky sles 3y ago A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing malicious…
CVE-2023-32435 high 9.5 KEVFIX rhel rocky sles 3y ago A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web …
CVE-2023-28198 high 8.0 FIX rhel slesdebian debian 3y ago A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 16.4 and iPadOS 16.4, macOS Ventura 13.3. Processing web content may lead to arbitrary code execution.
CVE-2022-32885 high 8.0 FIX rheldebian debianalmalinux almalinux 3y ago A memory corruption issue was addressed with improved validation. This issue is fixed in iOS 15.6 and iPadOS 15.6, macOS Monterey 12.5, Safari 15.6. Processing maliciously crafted web content may lea…
CVE-2023-2828 high 8.0 FIX rheldebian debian rocky 3y ago RHSA-2023:4102: bind security update (Important)
CVE-2022-40609 high 8.0 sles rhel 3y ago RHSA-2023:4103: java-1.8.0-ibm security update (Important)
CVE-2023-37211 high 8.0 FIX rhel rockydebian debian 3y ago Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these cou…
CVE-2023-37208 high 8.0 FIX rhel rockydebian debian 3y ago When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
CVE-2023-37207 high 8.0 FIX rhel rockydebian debian 3y ago A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofin…
CVE-2023-37202 high 8.0 FIX rhel rockydebian debian 3y ago Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects F…
CVE-2023-37201 high 8.0 FIX rhel rockydebian debian 3y ago An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
CVE-2023-33170 high 8.1 8.1 rhel rocky 3y ago RHSA-2023:4059: .NET 6.0 security, bug fix, and enhancement update (Important)
CVE-2023-1428 high 8.0 FIX rhel slesdebian debian 3y ago gRPC Reachable Assertion issue
CVE-2023-32731 high 8.0 FIX rhel slesdebian debian 3y ago Connection confusion in gRPC
CVE-2022-37967 high 8.0 FIX arch arch rocky sles 3y ago RHEA-2023:3850: krb5 bug fix update (Important)
CVE-2023-54325 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: crypto: qat - fix out-of-bounds read When preparing an AER-CTR request, the driver copies the key provided by the user into a dat…
CVE-2023-32233 high 8.0 FIX rhel rocky sles 3y ago In the Linux kernel through 6.3.1, a use-after-free in Netfilter nf_tables when processing batch requests can be abused to perform arbitrary read and write operations on kernel memory. Unprivileged l…
CVE-2023-2235 high 8.0 FIX rhel rocky sles 3y ago A use-after-free vulnerability in the Linux Kernel Performance Events system can be exploited to achieve local privilege escalation. The perf_group_detach function did not check the event's siblings…
CVE-2023-2194 high 8.0 FIX rhel rocky sles 3y ago An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the si…
CVE-2023-2124 high 8.0 FIX rhel rocky sles 3y ago An out-of-bounds memory access flaw was found in the Linux kernel’s XFS file system in how a user restores an XFS image after failure (with a dirty log journal). This flaw allows a local user to cras…
CVE-2023-2002 high 8.0 FIX rhel rocky sles 3y ago A vulnerability was found in the HCI sockets implementation due to a missing capability check in net/bluetooth/hci_sock.c in the Linux Kernel. This flaw allows an attacker to unauthorized execution o…
CVE-2023-32700 high 8.0 FIX rhel sles rocky 3y ago Important: texlive security update
CVE-2023-34416 high 8.0 FIX rhel rockydebian debian 3y ago Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these cou…
CVE-2023-34414 high 8.0 FIX rhel rockydebian debian 3y ago The error page for sites with invalid TLS certificates was missing the activation-delay Firefox uses to protect prompts and permission dialogs from attacks that exploit human response time delays. If…
CVE-2023-33128 high 8.0 rhel rocky 3y ago RHSA-2023:3593: .NET 7.0 security, bug fix, and enhancement update (Important)
CVE-2023-32032 high 8.0 rhel rocky 3y ago RHSA-2023:3593: .NET 7.0 security, bug fix, and enhancement update (Important)
CVE-2023-31147 high 8.0 FIX rheldebian debian rocky 3y ago Important: nodejs security update
CVE-2023-31130 high 8.0 FIX rheldebian debian rocky 3y ago Important: nodejs security update
CVE-2023-31124 high 8.0 FIX rheldebian debian rocky 3y ago Important: nodejs security update
CVE-2023-29337 high 8.0 rhel rockydebian debian 3y ago RHSA-2023:3593: .NET 7.0 security, bug fix, and enhancement update (Important)
CVE-2023-29331 high 8.0 rhel rocky 3y ago RHSA-2023:3593: .NET 7.0 security, bug fix, and enhancement update (Important)
CVE-2023-24936 high 8.0 rhel rocky 3y ago RHSA-2023:3593: .NET 7.0 security, bug fix, and enhancement update (Important)
CVE-2023-24329 high 8.0 FIX rhel rocky sles 3y ago An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
CVE-2023-32067 high 8.0 FIX rheldebian debian rocky 3y ago Important: nodejs security update
CVE-2023-32373 high 9.5 KEVFIX rhel rocky sles 3y ago A use-after-free issue was addressed with improved memory management. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS…
CVE-2023-28204 high 9.5 KEVFIX rhel rockydebian debian 3y ago An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 9.5, tvOS 16.5, macOS Ventura 13.4, iOS 15.7.6 and iPadOS 15.7.6, Safari 16.5, iOS 16.5 and iPadOS 1…
CVE-2023-24805 high 8.0 FIX rheldebian debian rocky 3y ago RHSA-2023:3425: cups-filters security update (Important)
CVE-2023-24532 high 8.0 FIX rhel slesdebian debian 3y ago RHSA-2023:3319: go-toolset:rhel8 security update (Important)
CVE-2023-29007 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:3246: git security update (Important)
CVE-2023-25815 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:3246: git security update (Important)
CVE-2023-25652 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:3246: git security update (Important)
CVE-2023-23946 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:3246: git security update (Important)
CVE-2023-22490 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:3246: git security update (Important)
CVE-2023-32215 high 8.0 FIX rhel rockydebian debian 3y ago Mozilla developers and community members Gabriele Svelto, Andrew Osmond, Emily McDonough, Sebastian Hengst, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefo…
CVE-2023-32213 high 8.0 FIX rhel rockydebian debian 3y ago When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
CVE-2023-32212 high 8.0 FIX rhel rockydebian debian 3y ago An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
CVE-2023-32211 high 8.0 FIX rhel rockydebian debian 3y ago A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
CVE-2023-32207 high 8.0 FIX rhel rockydebian debian 3y ago A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thund…
CVE-2023-32206 high 8.0 FIX rhel rockydebian debian 3y ago An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
CVE-2023-32205 high 8.0 FIX rhel rockydebian debian 3y ago In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox <…
CVE-2023-23454 high 8.0 FIX arch arch slesdebian debian 3y ago cbq_classify in net/sched/sch_cbq.c in the Linux kernel through 6.1.4 allows attackers to cause a denial of service (slab-out-of-bounds read) because of type confusion (non-negative numbers can somet…
CVE-2023-2295 high 8.0 FIX rhel rockyalmalinux almalinux 3y ago RHSA-2023:3107: libreswan security update (Important)
CVE-2023-1582 high 8.0 FIX slesdebian debianalmalinux almalinux 3y ago A race problem was found in fs/proc/task_mmu.c in the memory management sub-component in the Linux kernel. This issue may allow a local attacker with user privilege to cause a denial of service.
CVE-2022-50130 high 8.0 FIX slesdebian debian rhel 3y ago In the Linux kernel, the following vulnerability has been resolved: staging: fbtft: core: set smem_len before fb_deferred_io_init call The fbtft_framebuffer_alloc() calls fb_deferred_io_init() befo…
CVE-2022-41218 high 8.0 FIX arch arch slesdebian debian 3y ago In drivers/media/dvb-core/dmxdev.c in the Linux kernel through 5.19.10, there is a use-after-free caused by refcount races, affecting dvb_demux_open and dvb_dmxdev_release.
CVE-2022-25265 high 8.0 FIX debian debianalmalinux almalinux rhel 3y ago In the Linux kernel through 5.16.10, certain binary files may have the exec-all attribute if they were built in approximately 2003 (e.g., with GCC 3.2.2 and Linux kernel 2.4.20). This can cause execu…
CVE-2022-25147 high 8.0 FIX debian debian rhel rocky 3y ago RHSA-2023:3109: apr-util security update (Important)
CVE-2021-47221 high 8.0 FIX slesdebian debian rhel 3y ago In the Linux kernel, the following vulnerability has been resolved: mm/slub: actually fix freelist pointer vs redzoning It turns out that SLUB redzoning ("slub_debug=Z") checks from s->object_size …
CVE-2021-33656 high 8.0 FIX slesdebian debianalmalinux almalinux 3y ago When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds.
CVE-2021-3560 high 10.0 KEVEXPFIX arch arch sles rocky 3y ago Red Hat Polkit contains an incorrect authorization vulnerability through the bypassing of credential checks for D-Bus requests, allowing for privilege escalation.
CVE-2025-21867 high 8.0 FIX rhel slesdebian debian 3y ago Important: kernel security update
CVE-2023-53811 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Cap MSIX used to online CPUs + 1 The irdma driver can use a maximum number of msix vectors equal to num_online_cpus()…
CVE-2023-53809 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: l2tp: Avoid possible recursive deadlock in l2tp_tunnel_register() When a file descriptor of pppol2tp socket is passed as file des…
CVE-2023-53765 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: dm cache: free background tracker's queued work in btracker_destroy Otherwise the kernel can BUG with: [ 2245.426978] ==========…
CVE-2023-53634 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: bpf, arm64: Fixed a BTI error on returning to patched function When BPF_TRAMP_F_CALL_ORIG is set, BPF trampoline uses BLR to jump…
CVE-2023-53606 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: nfsd: clean up potential nfsd_file refcount leaks in COPY codepath There are two different flavors of the nfsd4_copy struct. One …
CVE-2023-53552 high 8.0 FIX rocky rhel sles 3y ago In the Linux kernel, the following vulnerability has been resolved: drm/i915: mark requests for GuC virtual engines to avoid use-after-free References to i915_requests may be trapped by userspace i…
CVE-2023-53393 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix mlx5_ib_get_hw_stats when used for device Currently, when mlx5_ib_get_hw_stats() is used for device (port_num = 0)…
CVE-2023-53381 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: NFSD: fix leaked reference count of nfsd4_ssc_umount_item The reference count of nfsd4_ssc_umount_item is not decremented on erro…
CVE-2023-53273 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: Drivers: vmbus: Check for channel allocation before looking up relids relid2channel() assumes vmbus channel array to be allocated…
CVE-2023-53083 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: nfsd: don't replace page in rq_pages if it's a continuation of last page The splice read calls nfsd_splice_actor to put the pages…
CVE-2023-53033 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_payload: incorrect arithmetics when fetching VLAN header bits If the offset + length goes over the ethernet + vlan…
CVE-2023-53030 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Avoid use of GFP_KERNEL in atomic context Using GFP_KERNEL in preemption disable context, causing below warning whe…
CVE-2023-53029 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix the use of GFP_KERNEL in atomic context on rt The commit 4af1b64f80fb ("octeontx2-pf: Fix lmtst ID used in aura…
CVE-2023-53021 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_taprio: fix possible use-after-free syzbot reported a nasty crash [1] in net_tx_action() which made little sense u…
CVE-2023-53020 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: l2tp: close all race conditions in l2tp_tunnel_register() The code in l2tp_tunnel_register() is racy in several ways: 1. It modi…
CVE-2023-52905 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: Fix resource leakage in VF driver unbind resources allocated like mcam entries to support the Ntuple feature and ha…
CVE-2023-25363 high 8.0 FIX rhel slesdebian debian 3y ago A use-after-free vulnerability in WebCore::RenderLayer::updateDescendantDependentFlags in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVE-2023-25362 high 8.0 FIX rhel slesdebian debian 3y ago A use-after-free vulnerability in WebCore::RenderLayer::repaintBlockSelectionGaps in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVE-2023-25361 high 8.0 FIX rhel slesdebian debian 3y ago A use-after-free vulnerability in WebCore::RenderLayer::setNextSibling in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVE-2023-25360 high 8.0 FIX rhel slesdebian debian 3y ago A use-after-free vulnerability in WebCore::RenderLayer::renderer in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVE-2023-25358 high 8.0 FIX rhel slesdebian debian 3y ago A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
CVE-2023-2513 high 8.0 FIX rhel slesdebian debian 3y ago A use-after-free vulnerability was found in the Linux kernel's ext4 filesystem in the way it handled the extra inode size for extended attributes. This flaw could allow a privileged local user to cau…
CVE-2023-2491 high 8.0 FIX rheldebian debianalmalinux almalinux 3y ago RHSA-2023:3104: emacs security update (Important)
CVE-2023-23920 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:1743: nodejs:14 security, bug fix, and enhancement update (Important)
CVE-2023-23918 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:1743: nodejs:14 security, bug fix, and enhancement update (Important)
CVE-2023-23518 high 8.0 FIX rhel slesdebian debian 3y ago The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS…
CVE-2023-23517 high 8.0 FIX rhel slesdebian debian 3y ago The issue was addressed with improved memory handling. This issue is fixed in macOS Monterey 12.6.3, macOS Ventura 13.2, watchOS 9.3, macOS Big Sur 11.7.3, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS…
CVE-2023-2319 high 8.0 rhel rocky 3y ago Important: pcs security and bug fix update
CVE-2023-22998 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel before 6.0.3, drivers/gpu/drm/virtio/virtgpu_object.c misinterprets the drm_gem_shmem_get_sg_table return value (expects it to be NULL in the error case, whereas it is actually an…
CVE-2023-2203 high 8.0 FIX rhel rocky sles 3y ago A flaw was found in the WebKitGTK package. An improper input validation issue may lead to a use-after-free vulnerability. This flaw allows attackers with network access to pass specially crafted web …
CVE-2023-22028 high 8.0 FIX rheldebian debian 3y ago RHSA-2023:3087: mysql:8.0 security, bug fix, and enhancement update (Important)