Show filters
601 Total Results
Displaying 131-140 of 601
Sort by:
Attacker Value
Unknown

CVE-2023-6779

Disclosure Date: January 31, 2024 (last updated February 09, 2024)
An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a message bigger than INT_MAX bytes, leading to an incorrect calculation of the buffer size to store the message, resulting in an application crash. This issue affects glibc 2.37 and newer.
Attacker Value
Unknown

CVE-2023-46838

Disclosure Date: January 29, 2024 (last updated February 14, 2025)
Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transferred data, these parts are directly translated into what Linux calls SKB fragments. Such converted request parts can, when for a particular SKB they are all of length zero, lead to a de-reference of NULL in core networking code.
Attacker Value
Unknown

CVE-2024-0813

Disclosure Date: January 24, 2024 (last updated January 30, 2024)
Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2024-0812

Disclosure Date: January 24, 2024 (last updated January 30, 2024)
Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Attacker Value
Unknown

CVE-2024-0811

Disclosure Date: January 24, 2024 (last updated January 30, 2024)
Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
Attacker Value
Unknown

CVE-2024-0809

Disclosure Date: January 24, 2024 (last updated January 30, 2024)
Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Attacker Value
Unknown

CVE-2024-0806

Disclosure Date: January 24, 2024 (last updated January 30, 2024)
Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2024-0805

Disclosure Date: January 24, 2024 (last updated January 30, 2024)
Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2024-0804

Disclosure Date: January 24, 2024 (last updated January 30, 2024)
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Attacker Value
Unknown

CVE-2023-39197

Disclosure Date: January 23, 2024 (last updated August 28, 2024)
An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information via the DCCP protocol.