Show filters
936 Total Results
Displaying 111-120 of 936
Sort by:
Attacker Value
Unknown
CVE-2023-4236
Disclosure Date: September 20, 2023 (last updated February 01, 2024)
A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load.
This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1.
0
Attacker Value
Unknown
CVE-2023-3341
Disclosure Date: September 20, 2023 (last updated February 17, 2024)
The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing `named` to terminate unexpectedly. Since each incoming control channel message is fully parsed before its contents are authenticated, exploiting this flaw does not require the attacker to hold a valid RNDC key; only network access to the control channel's configured TCP port is necessary.
This issue affects BIND 9 versions 9.2.0 through 9.16.43, 9.18.0 through 9.18.18, 9.19.0 through 9.19.16, 9.9.3-S1 through 9.16.43-S1, and 9.18.0-S1 through 9.18.18-S1.
0
Attacker Value
Unknown
CVE-2023-38039
Disclosure Date: September 15, 2023 (last updated April 02, 2024)
When curl retrieves an HTTP response, it stores the incoming headers so that
they can be accessed later via the libcurl headers API.
However, curl did not have a limit in how many or how large headers it would
accept in a response, allowing a malicious server to stream an endless series
of headers and eventually cause curl to run out of heap memory.
0
Attacker Value
Unknown
CVE-2023-4909
Disclosure Date: September 12, 2023 (last updated October 18, 2023)
Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
0
Attacker Value
Unknown
CVE-2023-4908
Disclosure Date: September 12, 2023 (last updated October 18, 2023)
Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
0
Attacker Value
Unknown
CVE-2023-4907
Disclosure Date: September 12, 2023 (last updated October 18, 2023)
Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
0
Attacker Value
Unknown
CVE-2023-4906
Disclosure Date: September 12, 2023 (last updated October 18, 2023)
Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
0
Attacker Value
Unknown
CVE-2023-4905
Disclosure Date: September 12, 2023 (last updated October 18, 2023)
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
0
Attacker Value
Unknown
CVE-2023-4903
Disclosure Date: September 12, 2023 (last updated October 18, 2023)
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
0
Attacker Value
Unknown
CVE-2023-4902
Disclosure Date: September 12, 2023 (last updated October 18, 2023)
Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
0