Show filters
1,213 Total Results
Displaying 181-190 of 1,213
Sort by:
Attacker Value
Unknown

CVE-2023-2731

Disclosure Date: May 17, 2023 (last updated February 25, 2025)
A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
Attacker Value
Unknown

CVE-2023-2700

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
Attacker Value
Unknown

CVE-2023-1729

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.
Attacker Value
Unknown

CVE-2023-2156

Disclosure Date: May 09, 2023 (last updated February 24, 2025)
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
Attacker Value
Unknown

CVE-2023-30944

Disclosure Date: May 02, 2023 (last updated February 24, 2025)
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
Attacker Value
Unknown

CVE-2023-30943

Disclosure Date: May 02, 2023 (last updated February 24, 2025)
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
Attacker Value
Unknown

CVE-2023-2194

Disclosure Date: April 20, 2023 (last updated February 24, 2025)
An out-of-bounds write vulnerability was found in the Linux kernel's SLIMpro I2C device driver. The userspace "data->block[0]" variable was not capped to a number between 0-255 and was used as the size of a memcpy, possibly writing beyond the end of dma_buffer. This flaw could allow a local privileged user to crash the system or potentially achieve code execution.
Attacker Value
Unknown

CVE-2023-1906

Disclosure Date: April 12, 2023 (last updated February 24, 2025)
A heap-based buffer overflow issue was discovered in ImageMagick's ImportMultiSpectralQuantum() function in MagickCore/quantum-import.c. An attacker could pass specially crafted file to convert, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
Attacker Value
Unknown

CVE-2023-0664

Disclosure Date: March 29, 2023 (last updated February 24, 2025)
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.
Attacker Value
Unknown

CVE-2023-0179

Disclosure Date: March 27, 2023 (last updated February 24, 2025)
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.