Show filters
1,878 Total Results
Displaying 151-160 of 1,878
Sort by:
Attacker Value
Unknown

CVE-2023-20811

Disclosure Date: August 07, 2023 (last updated October 08, 2023)
In IOMMU, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issue ID: DTV03692061.
Attacker Value
Unknown

CVE-2023-20810

Disclosure Date: August 07, 2023 (last updated October 08, 2023)
In IOMMU, there is a possible information disclosure due to improper input validation. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03692061; Issue ID: DTV03692061.
Attacker Value
Unknown

CVE-2023-20593

Disclosure Date: July 24, 2023 (last updated February 14, 2025)
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
Attacker Value
Unknown

CVE-2023-3106

Disclosure Date: July 12, 2023 (last updated April 25, 2024)
A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the message(sendmsg) for the XFRM_MSG_GETSA, XFRM_MSG_GETPOLICY type message, and the DUMP flag is set and can cause a denial of service or possibly another unspecified impact. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is unlikely.
Attacker Value
Unknown

CVE-2023-20716

Disclosure Date: June 06, 2023 (last updated February 25, 2025)
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07796883; Issue ID: ALPS07796883.
Attacker Value
Unknown

CVE-2023-20715

Disclosure Date: June 06, 2023 (last updated February 25, 2025)
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07796900; Issue ID: ALPS07796900.
Attacker Value
Unknown

CVE-2023-20712

Disclosure Date: June 06, 2023 (last updated February 25, 2025)
In wlan, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07796914; Issue ID: ALPS07796914.
Attacker Value
Unknown

CVE-2023-2295

Disclosure Date: May 17, 2023 (last updated February 25, 2025)
A vulnerability was found in the libreswan library. This security issue occurs when an IKEv1 Aggressive Mode packet is received with only unacceptable crypto algorithms, and the response packet is not sent with a zero responder SPI. When a subsequent packet is received where the sender reuses the libreswan responder SPI as its own initiator SPI, the pluto daemon state machine crashes. No remote code execution is possible. This CVE exists because of a CVE-2023-30570 security regression for libreswan package in Red Hat Enterprise Linux 8.8 and Red Hat Enterprise Linux 9.2.
Attacker Value
Unknown

CVE-2023-2700

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
Attacker Value
Unknown

CVE-2023-1906

Disclosure Date: April 12, 2023 (last updated February 24, 2025)
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.