Show filters
3,616 Total Results
Displaying 231-240 of 3,616
Sort by:
Attacker Value
Unknown

CVE-2023-6856

Disclosure Date: December 19, 2023 (last updated February 25, 2025)
The WebGL `DrawElementsInstanced` method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver. This issue could allow an attacker to perform remote code execution and sandbox escape. This vulnerability affects Firefox ESR < 115.6, Thunderbird < 115.6, and Firefox < 121.
Attacker Value
Unknown

CVE-2023-51385

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
Attacker Value
Unknown

CVE-2023-5115

Disclosure Date: December 18, 2023 (last updated February 25, 2025)
An absolute path traversal attack exists in the Ansible automation platform. This flaw allows an attacker to craft a malicious Ansible role and make the victim execute the role. A symlink can be used to overwrite a file outside of the extraction path.
Attacker Value
Unknown

CVE-2023-6478

Disclosure Date: December 13, 2023 (last updated February 25, 2025)
A flaw was found in xorg-server. A specially crafted request to RRChangeProviderProperty or RRChangeOutputProperty can trigger an integer overflow which may lead to a disclosure of sensitive information.
Attacker Value
Unknown

CVE-2023-6377

Disclosure Date: December 13, 2023 (last updated February 25, 2025)
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
Attacker Value
Unknown

CVE-2023-45866

Disclosure Date: December 08, 2023 (last updated February 25, 2025)
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Attacker Value
Unknown

CVE-2023-40462

Disclosure Date: December 04, 2023 (last updated February 25, 2025)
The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
Attacker Value
Unknown

CVE-2023-6212

Disclosure Date: November 21, 2023 (last updated February 25, 2025)
Memory safety bugs present in Firefox 119, Firefox ESR 115.4, and Thunderbird 115.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Attacker Value
Unknown

CVE-2023-6208

Disclosure Date: November 21, 2023 (last updated November 29, 2023)
When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
Attacker Value
Unknown

CVE-2023-6207

Disclosure Date: November 21, 2023 (last updated February 25, 2025)
Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.