CVEs from 2023
Total
6,107
critical
critical 240
high
high 1,530
medium
medium 1,393
low
low 32
% Critical
3.9%
% with KEV
2.7%
% with exploit
3.5%
Top products
- office 29
- office_long_term_servicing_channel 15
- 365_apps 14
- ftmg-esr50sxx 8
- ftmg-esn40sxx 8
- ftmg-esd25axx 8
- ftmg-esr40sxx 8
- ftmg-esd15axx 8
| CVE | Severity | CVSS | Risk | Flags | OS | Vendor | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-39319 | medium | — | 5.5 | 3y ago | Moderate: container-tools:rhel8 security update | |||
| CVE-2023-26966 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |||
| CVE-2023-54057 | medium | — | 5.5 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Add a length limitation for the ivrs_acpihid command-line parameter The 'acpiid' buffer in the parse_ivrs_acpihid func… | |||
| CVE-2023-53867 | medium | — | 5.5 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: ceph: fix potential use-after-free bug when trimming caps When trimming the caps and just after the 'session->s_cap_lock' is rele… | |||
| CVE-2023-38712 | medium | — | 5.5 | 3y ago | RHSA-2023:7052: libreswan security update (Moderate) | |||
| CVE-2023-2856 | medium | — | 5.5 | 3y ago | RHSA-2023:7015: wireshark security update (Moderate) | |||
| CVE-2023-2952 | medium | — | 5.5 | 3y ago | RHSA-2023:7015: wireshark security update (Moderate) | |||
| CVE-2023-1672 | medium | — | 5.5 | 3y ago | RHSA-2023:7022: tang security and bug fix update (Moderate) | |||
| CVE-2023-3138 | medium | — | 5.5 | 3y ago | RHSA-2023:7029: libX11 security update (Moderate) | |||
| CVE-2023-28100 | medium | — | 5.5 | 3y ago | RHSA-2023:7038: flatpak security, bug fix, and enhancement update (Moderate) | |||
| CVE-2023-28450 | medium | — | 5.5 | 3y ago | RHSA-2023:7046: dnsmasq security and bug fix update (Moderate) | |||
| CVE-2023-28879 | medium | — | 5.5 | 3y ago | RHSA-2023:7053: ghostscript security and bug fix update (Moderate) | |||
| CVE-2023-42669 | medium | — | 5.5 | 3y ago | RHSA-2023:7467: samba security update (Moderate) | |||
| CVE-2023-31484 | medium | — | 5.5 | 3y ago | RHSA-2024:3094: perl-CPAN security update (Moderate) | |||
| CVE-2023-0836 | medium | — | 5.5 | 3y ago | Moderate: haproxy security and bug fix update | |||
| CVE-2023-34966 | medium | — | 5.5 | 3y ago | RHSA-2023:7139: samba security, bug fix, and enhancement update (Moderate) | |||
| CVE-2023-26767 | medium | — | 5.5 | 3y ago | Buffer Overflow vulnerability found in Liblouis v.3.24.0 allows a remote attacker to cause a denial of service via the lou_logFile function at logginc.c endpoint. | |||
| CVE-2023-53089 | medium | — | 5.5 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: ext4: fix task hung in ext4_xattr_delete_inode Syzbot reported a hung task problem: =============================================… | |||
| CVE-2023-27534 | medium | — | 5.5 | 3y ago | A path traversal vulnerability exists in curl <8.0.0 SFTP implementation causes the tilde (~) character to be wrongly replaced when used as a prefix in the first path element, in addition to its inte… | |||
| CVE-2023-39975 | medium | — | 5.5 | 3y ago | Moderate: krb5 security and bug fix update | |||
| CVE-2023-29491 | medium | — | 5.5 | 3y ago | RHSA-2023:5249: ncurses security update (Moderate) | |||
| CVE-2023-28101 | medium | — | 5.5 | 3y ago | RHSA-2023:7038: flatpak security, bug fix, and enhancement update (Moderate) | |||
| CVE-2023-36054 | medium | — | 5.5 | 3y ago | Moderate: krb5 security and bug fix update | |||
| CVE-2023-3961 | medium | — | 5.5 | 3y ago | RHSA-2023:7467: samba security update (Moderate) | |||
| CVE-2023-53705 | medium | — | 5.5 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: ipv6: Fix out-of-bounds access in ipv6_find_tlv() optlen is fetched without checking whether there is more than one byte to parse… | |||
| CVE-2023-53746 | medium | — | 5.5 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: s390/vfio-ap: fix memory leak in vfio_ap device driver The device release callback function invoked to release the matrix device … | |||
| CVE-2023-2855 | medium | — | 5.5 | 3y ago | Moderate: wireshark security update | |||
| CVE-2023-27533 | medium | — | 5.5 | 3y ago | A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during serve… | |||
| CVE-2023-0668 | medium | — | 5.5 | 3y ago | Moderate: wireshark security update | |||
| CVE-2023-2858 | medium | — | 5.5 | 3y ago | RHSA-2023:7015: wireshark security update (Moderate) | |||
| CVE-2023-27536 | medium | — | 5.5 | 3y ago | An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to che… | |||
| CVE-2023-53392 | medium | — | 5.5 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: HID: intel-ish-hid: Fix kernel panic during warm reset During warm reset device->fw_client is set to NULL. If a bus driver is reg… | |||
| CVE-2023-53292 | medium | 5.5 | 5.5 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: blk-mq: fix NULL dereference on q->elevator in blk_mq_elv_switch_none After grabbing q->sysfs_lock, q->elevator may become NULL b… | |||
| CVE-2023-53224 | medium | — | 5.5 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: ext4: Fix function prototype mismatch for ext4_feat_ktype With clang's kernel control flow integrity (kCFI, CONFIG_CFI_CLANG), in… | |||
| CVE-2023-3750 | medium | — | 5.5 | 3y ago | Moderate: libvirt security, bug fix, and enhancement update | |||
| CVE-2023-53576 | medium | — | 5.5 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: null_blk: Always check queue mode setting from configfs Make sure to check device queue mode in the null_validate_conf() and retu… | |||
| CVE-2023-27371 | medium | — | 5.5 | 3y ago | RHSA-2023:7090: libmicrohttpd security update (Moderate) | |||
| CVE-2023-53205 | medium | — | 5.5 | 3y ago | In the Linux kernel, the following vulnerability has been resolved: KVM: s390/diag: fix racy access of physical cpu number in diag 9c handler We do check for target CPU == -1, but this might change… | |||
| CVE-2023-25173 | medium | — | 5.5 | 3y ago | RHSA-2023:6939: container-tools:rhel8 security and bug fix update (Moderate) | |||
| CVE-2023-1183 | medium | — | 5.5 | 3y ago | Moderate: libreoffice security update | |||
| CVE-2023-2255 | medium | — | 5.5 | 3y ago | Moderate: libreoffice security update | |||
| CVE-2023-31486 | medium | — | 5.5 | 3y ago | Moderate: perl-HTTP-Tiny security update | |||
| CVE-2023-23931 | medium | — | 5.5 | 3y ago | RHSA-2024:2985: python39:3.9 and python39-devel:3.9 security update (Moderate) | |||
| CVE-2023-2731 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |||
| CVE-2023-3316 | medium | — | 5.5 | 3y ago | Moderate: libtiff security update | |||
| CVE-2023-33460 | medium | — | 5.5 | 3y ago | RHSA-2023:7057: yajl security update (Moderate) | |||
| CVE-2023-0950 | medium | — | 5.5 | 3y ago | Moderate: libreoffice security update | |||
| CVE-2023-28370 | medium | — | 5.5 | 3y ago | Open redirect vulnerability in Tornado versions 6.3.1 and earlier allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having user acc… | |||
| CVE-2023-44271 | medium | — | 5.5 | 3y ago | RHSA-2024:3005: python-pillow security update (Moderate) | |||
| CVE-2023-3247 | medium | — | 5.5 | 3y ago | RHSA-2024:10952: php:7.4 security update (Moderate) | |||
| CVE-2023-0567 | medium | — | 5.5 | 3y ago | RHSA-2024:10952: php:7.4 security update (Moderate) | |||
| CVE-2023-0568 | medium | — | 5.5 | 3y ago | RHSA-2024:10952: php:7.4 security update (Moderate) | |||
| CVE-2023-3823 | medium | — | 5.5 | 3y ago | RHSA-2024:10952: php:7.4 security update (Moderate) | |||
| CVE-2023-3824 | medium | — | 5.5 | 3y ago | RHSA-2024:10952: php:7.4 security update (Moderate) | |||
| CVE-2023-22025 | medium | — | 5.5 | 3y ago | RHSA-2023:6887: java-21-openjdk security and bug fix update (Moderate) | |||
| CVE-2023-22067 | medium | — | 5.5 | 3y ago | RHSA-2024:0866: java-1.8.0-ibm security update (Moderate) | |||
| CVE-2023-29409 | medium | — | 5.5 | 3y ago | Moderate: container-tools:rhel8 security update | |||
| CVE-2023-39323 | medium | — | 5.5 | 3y ago | RHBA-2023:6928: go-toolset:rhel8 bug fix and enhancement update (Moderate) | |||
| CVE-2023-36799 | medium | — | 5.5 | 3y ago | RHSA-2023:6247: .NET 7.0 security update (Moderate) | |||
| CVE-2023-20593 | medium | — | 5.5 | 3y ago | Moderate: linux-firmware security update | |||
| CVE-2023-2603 | medium | — | 5.5 | 3y ago | RHSA-2023:4524: libcap security update (Moderate) | |||
| CVE-2023-2602 | medium | — | 5.5 | 3y ago | RHSA-2023:4524: libcap security update (Moderate) | |||
| CVE-2023-30630 | medium | — | 5.5 | 3y ago | RHSA-2023:5252: dmidecode security update (Moderate) | |||
| CVE-2023-38201 | medium | — | 5.5 | 3y ago | Moderate: keylime security update | |||
| CVE-2023-38200 | medium | — | 5.5 | 3y ago | Moderate: keylime security update | |||
| CVE-2023-38633 | medium | — | 5.5 | 3y ago | Moderate: librsvg2 security update | |||
| CVE-2023-29303 | medium | 5.5 | 5.5 | 3y ago | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker c… | |||
| CVE-2023-38245 | medium | 5.5 | 5.5 | 3y ago | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulner… | |||
| CVE-2023-38238 | medium | 5.5 | 5.5 | 3y ago | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use-After-Free vulnerability that could lead to disclosure of sensitive memory. An attacker c… | |||
| CVE-2023-38236 | medium | 5.5 | 5.5 | 3y ago | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attac… | |||
| CVE-2023-38235 | medium | 5.5 | 5.5 | 3y ago | Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attac… | |||
| CVE-2023-34969 | medium | — | 5.5 | 3y ago | D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor … | |||
| CVE-2023-22652 | medium | — | 5.5 | 3y ago | Moderate: libeconf security update | |||
| CVE-2023-29469 | medium | — | 5.5 | 3y ago | An issue was discovered in libxml2 before 2.10.4. When hashing empty dict strings in a crafted XML document, xmlDictComputeFastKey in dict.c can produce non-deterministic values, leading to various l… | |||
| CVE-2023-28484 | medium | — | 5.5 | 3y ago | In libxml2 before 2.10.4, parsing of certain invalid XSD schemas can lead to a NULL pointer dereference and subsequently a segfault. This occurs in xmlSchemaFixupComplexType in xmlschemas.c. | |||
| CVE-2023-32681 | medium | — | 5.5 | 3y ago | Moderate: python-requests security update | |||
| CVE-2023-30079 | medium | — | 5.5 | 3y ago | Moderate: libeconf security update | |||
| CVE-2023-28321 | medium | — | 5.5 | 3y ago | An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl… | |||
| CVE-2023-28322 | medium | — | 5.5 | 3y ago | An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even whe… | |||
| CVE-2023-30590 | medium | — | 5.5 | 3y ago | Moderate: nodejs:18 security, bug fix, and enhancement update | |||
| CVE-2023-30589 | medium | — | 5.5 | 3y ago | Moderate: nodejs:18 security, bug fix, and enhancement update | |||
| CVE-2023-30588 | medium | — | 5.5 | 3y ago | Moderate: nodejs:18 security, bug fix, and enhancement update | |||
| CVE-2023-30581 | medium | — | 5.5 | 3y ago | Moderate: nodejs:18 security, bug fix, and enhancement update | |||
| CVE-2023-3347 | medium | — | 5.5 | 3y ago | RHSA-2023:4328: samba security and bug fix update (Moderate) | |||
| CVE-2023-25193 | medium | — | 5.5 | 3y ago | RHSA-2024:2980: harfbuzz security update (Moderate) | |||
| CVE-2023-22044 | medium | — | 5.5 | 3y ago | RHSA-2023:4159: java-17-openjdk security and bug fix update (Moderate) | |||
| CVE-2023-3128 | medium | — | 5.5 | 3y ago | RHSA-2023:6972: grafana security and enhancement update (Moderate) | |||
| CVE-2023-33162 | medium | 5.5 | 5.5 | 3y ago | Microsoft Excel Information Disclosure Vulnerability | |||
| CVE-2023-36617 | medium | — | 5.5 | 3y ago | RHSA-2024:4499: ruby security update (Moderate) | |||
| CVE-2023-26604 | medium | — | 5.5 | 3y ago | systemd before 247 does not adequately block local privilege escalation for some Sudo configurations, e.g., plausible sudoers files in which the "systemctl status" command may be executed. Specifical… | |||
| CVE-2023-0466 | medium | — | 5.5 | 3y ago | Moderate: openssl security and bug fix update | |||
| CVE-2023-1255 | medium | — | 5.5 | 3y ago | Moderate: openssl security and bug fix update | |||
| CVE-2023-0464 | medium | — | 5.5 | 3y ago | Moderate: openssl security and bug fix update | |||
| CVE-2023-2650 | medium | — | 5.5 | 3y ago | Moderate: openssl security and bug fix update | |||
| CVE-2023-0465 | medium | — | 5.5 | 3y ago | Moderate: openssl security and bug fix update | |||
| CVE-2023-2454 | medium | — | 5.5 | 3y ago | Moderate: postgresql:15 security update | |||
| CVE-2023-0803 | medium | — | 5.5 | 3y ago | RHSA-2023:5353: libtiff security update (Moderate) | |||
| CVE-2023-2455 | medium | — | 5.5 | 3y ago | Moderate: postgresql:15 security update | |||
| CVE-2023-0800 | medium | — | 5.5 | 3y ago | RHSA-2023:5353: libtiff security update (Moderate) | |||
| CVE-2023-2700 | medium | — | 5.5 | 3y ago | RHSA-2023:3822: virt:rhel and virt-devel:rhel security and bug fix update (Moderate) |