Show filters
410 Total Results
Displaying 231-240 of 410
Sort by:
Attacker Value
Unknown
CVE-2023-46218
Disclosure Date: December 07, 2023 (last updated February 14, 2025)
This flaw allows a malicious HTTP server to set "super cookies" in curl that
are then passed back to more origins than what is otherwise allowed or
possible. This allows a site to set cookies that then would get sent to
different and unrelated sites and domains.
It could do this by exploiting a mixed case flaw in curl's function that
verifies a given cookie domain against the Public Suffix List (PSL). For
example a cookie could be set with `domain=co.UK` when the URL used a lower
case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
0
Attacker Value
Unknown
CVE-2023-6512
Disclosure Date: December 06, 2023 (last updated December 12, 2023)
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)
0
Attacker Value
Unknown
CVE-2023-6511
Disclosure Date: December 06, 2023 (last updated December 12, 2023)
Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
0
Attacker Value
Unknown
CVE-2023-6510
Disclosure Date: December 06, 2023 (last updated December 12, 2023)
Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
0
Attacker Value
Unknown
CVE-2023-6509
Disclosure Date: December 06, 2023 (last updated December 12, 2023)
Use after free in Side Panel Search in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: High)
0
Attacker Value
Unknown
CVE-2023-6508
Disclosure Date: December 06, 2023 (last updated December 12, 2023)
Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
0
Attacker Value
Unknown
CVE-2023-42917
Disclosure Date: November 30, 2023 (last updated June 27, 2024)
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
0
Attacker Value
Unknown
CVE-2023-6351
Disclosure Date: November 29, 2023 (last updated February 25, 2025)
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
0
Attacker Value
Unknown
CVE-2023-6350
Disclosure Date: November 29, 2023 (last updated February 25, 2025)
Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
0
Attacker Value
Unknown
CVE-2023-6348
Disclosure Date: November 29, 2023 (last updated February 25, 2025)
Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
0