Search

Found 9,908 results in 1047ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2023-5730 high 8.0 FIX rhelalmalinux almalinuxdebian debian 3y ago Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thunderbird 115.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2023-5728 high 8.0 FIX rhelalmalinux almalinuxdebian debian 3y ago During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR…
CVE-2023-5725 high 8.0 FIX rhelalmalinux almalinuxdebian debian 3y ago A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox E…
CVE-2023-5724 high 8.0 FIX rhelalmalinux almalinuxdebian debian 3y ago Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird <…
CVE-2023-5721 high 8.0 FIX rheldebian debian sles 3y ago It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an insufficient activation-delay. This vulnerability affects Firefox < 119, Fir…
CVE-2022-40284 high 8.0 FIX rocky rhel sles 3y ago RHSA-2023:5264: virt:rhel and virt-devel:rhel security and bug fix update (Important)
CVE-2023-46136 high 7.5 7.5 FIX slesdebian debian palletsprojects 3y ago Werkzeug is a comprehensive WSGI web application library. If an upload of a file that starts with CR or LF and then is followed by megabytes of data without these characters: all of these bytes are a…
CVE-2023-0662 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago RHSA-2023:5927: php:8.0 security update (Important)
CVE-2023-45143 high 8.0 FIX rocky rhel sles 3y ago RHSA-2023:7205: nodejs:20 security update (Important)
CVE-2023-39333 high 8.0 FIX rocky rhel sles 3y ago RHSA-2023:7205: nodejs:20 security update (Important)
CVE-2023-38552 high 8.0 FIX rocky rhel sles 3y ago RHSA-2023:7205: nodejs:20 security update (Important)
CVE-2023-45898 high 7.8 7.8 FIX debian debian linux-kernel 3y ago The Linux kernel before 6.5.4 has an es1 use-after-free in fs/ext4/extents_status.c, related to ext4_es_insert_extent.
CVE-2023-39325 high 8.0 FIX rhel rocky sles 3y ago Important: go-toolset and golang security and bug fix update
CVE-2023-5157 high 8.0 FIX rocky rhelalmalinux almalinux 3y ago RHSA-2023:5683: mariadb:10.5 security update (Important)
CVE-2023-3341 high 8.0 FIX rheldebian debian sles 3y ago Important: bind security update
CVE-2022-47015 high 8.0 FIX rocky rhelalmalinux almalinux 3y ago MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.
CVE-2022-38791 high 8.0 FIX rocky rhelalmalinux almalinux 3y ago RHSA-2023:5683: mariadb:10.5 security update (Important)
CVE-2022-32091 high 8.0 FIX rocky rhelalmalinux almalinux 3y ago RHSA-2023:5683: mariadb:10.5 security update (Important)
CVE-2022-32089 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago RHSA-2023:5683: mariadb:10.5 security update (Important)
CVE-2022-32084 high 8.0 FIX rocky rhelalmalinux almalinux 3y ago RHSA-2023:5683: mariadb:10.5 security update (Important)
CVE-2022-32082 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:5683: mariadb:10.5 security update (Important)
CVE-2022-32081 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:5683: mariadb:10.5 security update (Important)
CVE-2023-44488 high 8.0 FIX rocky rhel sles 3y ago RHSA-2023:6194: thunderbird security update (Important)
CVE-2023-43615 high 7.5 7.5 FIX debian debianfedora fedora armtrustedfirmware 3y ago Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
CVE-2023-4911 high 7.8 10.0 KEVEXPFIX rhel rocky sles gnuredhatnetapp 3y ago GNU C Library's dynamic loader ld.so contains a buffer overflow vulnerability when processing the GLIBC_TUNABLES environment variable, allowing a local attacker to execute code with elevated privileg…
CVE-2023-40217 high 8.0 FIX rocky rhel sles 3y ago An issue was discovered in Python before 3.8.18, 3.9.x before 3.9.18, 3.10.x before 3.10.13, and 3.11.x before 3.11.5. It primarily affects servers (such as HTTP servers) that use TLS client authenti…
CVE-2023-36664 high 8.0 FIX rhel slesdebian debian 3y ago Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
CVE-2023-5217 high 9.5 KEVFIX rocky rhelalmalinux almalinux 3y ago Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Ch…
CVE-2023-5176 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2023-5171 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerabil…
CVE-2023-5169 high 8.0 FIX rhel rockydebian debian 3y ago A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vul…
CVE-2023-3600 high 8.0 FIX rhel rockydebian debian 3y ago During the worker lifecycle, a use-after-free condition could have occurred, which could have led to a potentially exploitable crash. This vulnerability affects Firefox < 115.0.2, Firefox ESR < 115.0…
CVE-2023-32559 high 8.0 FIX rocky rhelalmalinux almalinux 3y ago RHSA-2023:5362: nodejs:18 security, bug fix, and enhancement update (Important)
CVE-2023-32006 high 8.0 FIX rocky rhel sles 3y ago RHSA-2023:5362: nodejs:18 security, bug fix, and enhancement update (Important)
CVE-2023-32002 high 8.0 FIX rocky rhel sles 3y ago RHSA-2023:5362: nodejs:18 security, bug fix, and enhancement update (Important)
CVE-2022-25883 high 8.0 FIX rocky rhel sles 3y ago RHSA-2023:5362: nodejs:18 security, bug fix, and enhancement update (Important)
CVE-2023-41419 high 8.0 FIX slesdebian debian rhel 3y ago RHSA-2024:8834: python-gevent security update (Important)
CVE-2019-19450 high 8.0 FIX slesdebian debian rhel 3y ago RHSA-2023:5790: python-reportlab security update (Important)
CVE-2023-20900 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:5312: open-vm-tools security update (Important)
CVE-2023-38802 high 8.0 FIX rheldebian debian sles 3y ago FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
CVE-2023-53769 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: virt/coco/sev-guest: Double-buffer messages The encryption algorithms read and write directly to shared unencrypted memory, which…
CVE-2023-53556 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: iavf: Fix use-after-free in free_netdev We do netif_napi_add() for all allocated q_vectors[], but potentially do netif_napi_del()…
CVE-2023-53383 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: irqchip/gicv3: Workaround for NVIDIA erratum T241-FABRIC-4 The T241 platform suffers from the T241-FABRIC-4 erratum which causes …
CVE-2023-4863 high 9.5 KEVFIX rheldebian debian rocky 3y ago Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium securi…
CVE-2023-44466 high 8.0 FIX rheldebian debian 3y ago An issue was discovered in net/ceph/messenger_v2.c in the Linux kernel before 6.4.5. There is an integer signedness error, leading to a buffer overflow and remote code execution via HELLO or one of t…
CVE-2023-4147 high 8.0 FIX rhel sles rocky 3y ago A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID. This flaw allows a local user to crash or escalate their privileges on the sy…
CVE-2023-4004 high 8.0 FIX rhel rocky sles 3y ago A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a loc…
CVE-2023-3776 high 8.0 FIX rhel rocky sles 3y ago A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, fw_set_parms() will immediately …
CVE-2023-3610 high 8.0 FIX rhel sles rocky 3y ago A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Flaw in the error handling of bound chains causes a use-af…
CVE-2023-35001 high 8.0 FIX rhel rocky sles 3y ago Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace
CVE-2023-3390 high 8.0 FIX rhel rocky sles 3y ago A use-after-free vulnerability was found in the Linux kernel's netfilter subsystem in net/netfilter/nf_tables_api.c. Mishandled error handling with NFT_MSG_NEWRULE makes it possible to use a danglin…
CVE-2023-3354 high 8.0 FIX rocky rhel sles 3y ago A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the …
CVE-2023-31248 high 8.0 FIX rhel sles rocky 3y ago Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespa…
CVE-2023-21102 high 8.0 FIX rhel sles rocky 3y ago In __efi_rt_asm_wrapper of efi-rt-wrapper.S, there is a possible bypass of shadow stack protection due to a logic error in the code. This could lead to local escalation of privilege with no additiona…
CVE-2023-1637 high 8.0 FIX rhel sles rocky 3y ago A flaw that boot CPU could be vulnerable for the speculative execution behavior kind of attacks in the Linux kernel X86 CPU Power management options functionality was found in the way user resuming C…
CVE-2022-50661 high 8.0 FIX rhel slesdebian debian 3y ago In the Linux kernel, the following vulnerability has been resolved: seccomp: Move copy_seccomp() to no failure path. Our syzbot instance reported memory leaks in do_seccomp() [0], similar to the re…
CVE-2020-22219 high 8.0 FIX rhel slesdebian debian 3y ago RHSA-2023:5046: flac security update (Important)
CVE-2023-23908 high 8.0 FIX rhel rocky sles 3y ago RHEA-2023:4995: microcode_ctl bug fix and enhancement update (Important)
CVE-2022-41804 high 8.0 FIX rhel rocky sles 3y ago RHEA-2023:4995: microcode_ctl bug fix and enhancement update (Important)
CVE-2022-40982 high 8.0 FIX rhel rocky sles 3y ago Information exposure through microarchitectural state after transient execution in certain vector execution units for some Intel(R) Processors may allow an authenticated user to potentially enable in…
CVE-2023-4585 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago Memory safety bugs present in Firefox 116, Firefox ESR 115.1, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2023-4584 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago Memory safety bugs present in Firefox 116, Firefox ESR 102.14, Firefox ESR 115.1, Thunderbird 102.14, and Thunderbird 115.1. Some of these bugs showed evidence of memory corruption and we presume tha…
CVE-2023-4583 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago When checking if the Browsing Context had been discarded in `HttpBaseChannel`, if the load group was not available then it was assumed to have already been discarded which was not always the case for…
CVE-2023-4581 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago Excel `.xll` add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded without any warning of their potential harm. This vulnerability affects …
CVE-2023-4580 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115…
CVE-2023-4578 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none i…
CVE-2023-4577 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable cras…
CVE-2023-4575 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago When creating a callback over IPC for showing the File Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of th…
CVE-2023-4574 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago When creating a callback over IPC for showing the Color Picker window, multiple of the same callbacks could have been created at a time and eventually all simultaneously destroyed as soon as one of t…
CVE-2023-4573 high 8.0 FIX rhelalmalinux almalinux rocky 3y ago When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affec…
CVE-2023-4053 high 8.0 FIX rhel rockydebian debian 3y ago A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofi…
CVE-2023-4051 high 8.0 FIX rhel rockydebian debian 3y ago A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116…
CVE-2023-32360 high 8.0 FIX rheldebian debian rocky 3y ago RHSA-2023:4864: cups security update (Important)
CVE-2023-38497 high 8.0 FIX rheldebian debian rocky 3y ago Cargo downloads the Rust project’s dependencies and compiles the project. Cargo prior to version 0.72.2, bundled with Rust prior to version 1.71.1, did not respect the umask when extracting crate arc…
CVE-2023-40267 high 8.0 FIX rocky slesdebian debian 3y ago GitPython before 3.1.32 does not block insecure non-multi options in clone and clone_from. NOTE: this issue exists because of an incomplete fix for CVE-2022-24439.
CVE-2023-33953 high 8.0 rhel slesdebian debian 3y ago Excessive Iteration in gRPC
CVE-2023-38403 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:4570: iperf3 security update (Important)
CVE-2023-1829 high 8.0 FIX rocky slesdebian debian 3y ago A use-after-free vulnerability in the Linux Kernel traffic control index filter (tcindex) can be exploited to achieve local privilege escalation. The tcindex_delete function which does not properly d…
CVE-2023-1281 high 8.0 FIX rocky slesdebian debian 3y ago Use After Free vulnerability in Linux kernel traffic control index filter (tcindex) allows Privilege Escalation. The imperfect hash area can be updated while packets are traversing, which will cause …
CVE-2023-3417 high 8.0 FIX rhel rocky sles 3y ago RHSA-2023:4497: thunderbird security update (Important)
CVE-2023-4057 high 8.0 FIX rhel rockydebian debian 3y ago Memory safety bugs present in Firefox 115, Firefox ESR 115.0, and Thunderbird 115.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could…
CVE-2023-4056 high 8.0 FIX rhel rockydebian debian 3y ago Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume tha…
CVE-2023-4055 high 8.0 FIX rhel rockydebian debian 3y ago When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused request…
CVE-2023-4050 high 8.0 FIX rhel rockydebian debian 3y ago In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulner…
CVE-2023-4049 high 8.0 FIX rhel rockydebian debian 3y ago Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox …
CVE-2023-4048 high 8.0 FIX rhel rockydebian debian 3y ago An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR…
CVE-2023-4047 high 8.0 FIX rhel rockydebian debian 3y ago A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, a…
CVE-2023-4046 high 8.0 FIX rhel rockydebian debian 3y ago In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process…
CVE-2023-4045 high 8.0 FIX rhel rockydebian debian 3y ago Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox…
CVE-2023-38408 high 8.0 FIX rhel rocky sles 3y ago The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Co…
CVE-2023-37464 high 8.0 FIX rheldebian debian rocky 3y ago RHSA-2023:4418: mod_auth_openidc:2.3 security update (Important)
CVE-2023-35788 high 8.0 FIX rhel rocky sles 3y ago Important: kernel security, bug fix, and enhancement update
CVE-2023-3090 high 8.0 FIX rhel rocky sles 3y ago Important: kernel security, bug fix, and enhancement update
CVE-2023-1998 high 9.0 EXPFIX rhel sles rocky 3y ago Important: kernel security, bug fix, and enhancement update
CVE-2023-0458 high 8.0 FIX rhel sles rocky 3y ago Important: kernel security, bug fix, and enhancement update
CVE-2022-45869 high 8.0 FIX rhel slesdebian debian 3y ago Important: kernel security, bug fix, and enhancement update
CVE-2025-31215 high 8.0 FIX rhelarch arch sles 3y ago The issue was addressed with improved checks. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing malici…
CVE-2025-31206 high 8.0 FIX rhelarch arch sles 3y ago A type confusion issue was addressed with improved state handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, iPadOS 17.7.7, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11…
CVE-2025-31204 high 8.0 FIX rhelarch arch sles 3y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.5, iOS 18.5 and iPadOS 18.5, macOS Sequoia 15.5, tvOS 18.5, visionOS 2.5, watchOS 11.5. Processing maliciously …
CVE-2025-24264 high 8.0 FIX rhel slesdebian debian 3y ago The issue was addressed with improved memory handling. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processi…