Show filters
5,420 Total Results
Displaying 151-160 of 5,420
Sort by:
Attacker Value
Unknown
CVE-2023-4503
Disclosure Date: February 06, 2024 (last updated May 03, 2024)
An improper initialization vulnerability was found in Galleon. When using Galleon to provision custom EAP or EAP-XP servers, the servers are created unsecured. This issue could allow an attacker to access remote HTTP services available from the server.
0
Attacker Value
Unknown
CVE-2023-50782
Disclosure Date: February 05, 2024 (last updated September 06, 2024)
A flaw was found in the python-cryptography package. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
0
Attacker Value
Unknown
CVE-2023-50781
Disclosure Date: February 05, 2024 (last updated April 25, 2024)
A flaw was found in m2crypto. This issue may allow a remote attacker to decrypt captured messages in TLS servers that use RSA key exchanges, which may lead to exposure of confidential or sensitive data.
0
Attacker Value
Unknown
CVE-2023-7216
Disclosure Date: February 05, 2024 (last updated September 19, 2024)
A path traversal vulnerability was found in the CPIO utility. This issue could allow a remote unauthenticated attacker to trick a user into opening a specially crafted archive. During the extraction process, the archiver could follow symlinks outside of the intended directory, which allows files to be written in arbitrary directories through symlinks.
0
Attacker Value
Unknown
CVE-2023-6240
Disclosure Date: February 04, 2024 (last updated June 05, 2024)
A Marvin vulnerability side-channel leakage was found in the RSA decryption operation in the Linux Kernel. This issue may allow a network attacker to decrypt ciphertexts or forge signatures, limiting the services that use that private key.
0
Attacker Value
Unknown
CVE-2023-5992
Disclosure Date: January 31, 2024 (last updated October 10, 2024)
A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant. This issue may result in the potential leak of private data.
0
Attacker Value
Unknown
CVE-2024-0914
Disclosure Date: January 31, 2024 (last updated April 25, 2024)
A timing side-channel vulnerability has been discovered in the opencryptoki package while processing RSA PKCS#1 v1.5 padded ciphertexts. This flaw could potentially enable unauthorized RSA ciphertext decryption or signing, even without access to the corresponding private key.
0
Attacker Value
Unknown
CVE-2024-0564
Disclosure Date: January 30, 2024 (last updated April 25, 2024)
A flaw was found in the Linux kernel's memory deduplication mechanism. The max page sharing of Kernel Samepage Merging (KSM), added in Linux kernel version 4.4.0-96.119, can create a side channel. When the attacker and the victim share the same host and the default setting of KSM is "max page sharing=256", it is possible for the attacker to time the unmap to merge with the victim's page. The unmapping time depends on whether it merges with the victim's page and additional physical pages are created beyond the KSM's "max page share". Through these operations, the attacker can leak the victim's page.
0
Attacker Value
Unknown
CVE-2023-40551
Disclosure Date: January 29, 2024 (last updated April 29, 2024)
A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.
0
Attacker Value
Unknown
CVE-2023-40550
Disclosure Date: January 29, 2024 (last updated April 29, 2024)
An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensitive data during the system's boot phase.
0